Description
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `tf.raw_ops.CTCLoss` allows an attacker to trigger an OOB read from heap. The fix will be included in TensorFlow 2.5.0. We will also cherrypick these commits on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.
References (3)
Core 3
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-vvg4-vgrv-xfr7
Patch, Third Party Advisory x_refsource_misc
https://github.com/tensorflow/tensorflow/commit/14607c0707040d775e06b6817325640cb4b5864c
Patch, Third Party Advisory x_refsource_misc
https://github.com/tensorflow/tensorflow/commit/4504a081af71514bb1828048363e6540f797005b
Scores
CVSS v3
6.3
EPSS
0.0024
EPSS Percentile
14.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-125
CWE-665
Status
published
Products (4)
google/tensorflow
< 2.1.4
pypi/tensorflow
0 - 2.1.4PyPI
pypi/tensorflow-cpu
0 - 2.1.4PyPI
pypi/tensorflow-gpu
0 - 2.1.4PyPI
Published
May 14, 2021
Tracked Since
Feb 18, 2026