BIT-tensorflow-2021-41215
Dashboard / Vulnerabilities / BIT-tensorflow-2021-41215
BIT-tensorflow-2021-41215
Summary: Null pointer exception in `DeserializeSparse`
Details: TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `DeserializeSparse` can trigger a null pointer dereference. This is because the shape inference function assumes that the `serialize_sparse` tensor is a tensor with positive rank (and having `3` as the last dimension). The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
References: https://github.com/tensorflow/tensorflow/commit/d3738dd70f1c9ceb547258cbb82d853da8771850, https://github.com/tensorflow/tensorflow/security/advisories/GHSA-x3v8-c8qx-3j3r, https://nvd.nist.gov/vuln/detail/CVE-2021-41215
Affected packages
Package
Name: tensorflow
Purl: pkg:bitnami/tensorflow
Affected ranges
Type: SEMVER
Events:
