BIT-tensorflow-2021-37649

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tensorflow/BIT-tensorflow-2021-37649.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tensorflow-2021-37649
Aliases
Published
2024-03-06T11:17:35.508Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

TensorFlow is an end-to-end open source platform for machine learning. The code for tf.raw_ops.UncompressElement can be made to trigger a null pointer dereference. The implementation obtains a pointer to a CompressedElement from a Variant tensor and then proceeds to dereference it for decompressing. There is no check that the Variant tensor contained a CompressedElement, so the pointer is actually nullptr. We have patched the issue in GitHub commit 7bdf50bb4f5c54a4997c379092888546c97c3ebd. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.

References

Affected packages

Bitnami / tensorflow

Package

Name
tensorflow
Purl
pkg:bitnami/tensorflow

Severity

  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
2.3.0
Fixed
2.3.4
Introduced
2.4.0
Fixed
2.4.3
Type
SEMVER
Events
Introduced
2.5.0
Last affected
2.5.0
Introduced
2.6.0-rc0
Last affected
2.6.0-rc0
Introduced
2.6.0-rc1
Last affected
2.6.0-rc1
Introduced
2.6.0-rc2
Last affected
2.6.0-rc2