BIT-tensorflow-2021-37684
Dashboard / Vulnerabilities / BIT-tensorflow-2021-37684
BIT-tensorflow-2021-37684
Summary: Division by zero in TensorFlow Lite pooling operations
Details: TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementations of pooling in TFLite are vulnerable to division by 0 errors as there are no checks for divisors not being 0. We have patched the issue in GitHub commit [dfa22b348b70bb89d6d6ec0ff53973bacb4f4695](https://github.com/tensorflow/tensorflow/commit/dfa22b348b70bb89d6d6ec0ff53973bacb4f4695). The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
References: https://github.com/tensorflow/tensorflow/security/advisories/GHSA-q7f7-544h-67h9, https://nvd.nist.gov/vuln/detail/CVE-2021-37684
Affected packages
Package
Name: tensorflow
Purl: pkg:bitnami/tensorflow
Affected ranges
Type: SEMVER
Events:
