CVE-2021-29526
LOWTensorFlow < 2.1.4 - Denial of Service via Division by Zero in Conv2D
Title source: llmDescription
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a division by 0 in `tf.raw_ops.Conv2D`. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/988087bd83f144af14087fe4fecee2d250d93737/tensorflow/core/kernels/conv_ops.cc#L261-L263) does a division by a quantity that is controlled by the caller. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.
References (2)
Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-4vf2-4xcg-65cx
Patch, Third Party Advisory x_refsource_misc
https://github.com/tensorflow/tensorflow/commit/b12aa1d44352de21d1a6faaf04172d8c2508b42b
Scores
CVSS v3
2.5
EPSS
0.0020
EPSS Percentile
9.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-369
Status
published
Products (4)
google/tensorflow
< 2.1.4
pypi/tensorflow
0 - 2.1.4PyPI
pypi/tensorflow-cpu
0 - 2.1.4PyPI
pypi/tensorflow-gpu
0 - 2.1.4PyPI
Published
May 14, 2021
Tracked Since
Feb 18, 2026