CVE-2021-41207
MEDIUMTensorFlow 2.4.0-2.4.3, 2.6.0 - Divide By Zero in ParallelConcat
Title source: llmDescription
TensorFlow is an open source platform for machine learning. In affected versions the implementation of `ParallelConcat` misses some input validation and can produce a division by 0. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/tensorflow/tensorflow/commit/f2c3931113eaafe9ef558faaddd48e00a6606235
Third Party Advisory x_refsource_confirm
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-7v94-64hj-m82h
Scores
CVSS v3
5.5
EPSS
0.0014
EPSS Percentile
3.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-369
Status
published
Products (5)
google/tensorflow
2.7.0 rc0 (2 CPE variants)
google/tensorflow
2.4.0 - 2.4.4
pypi/tensorflow
2.6.0 - 2.6.1PyPI
pypi/tensorflow-cpu
0 - 2.4.4PyPI
pypi/tensorflow-gpu
0 - 2.4.4PyPI
Published
Nov 05, 2021
Tracked Since
Feb 18, 2026