CVE-2021-37688
Null pointer dereference in TensorFlow Lite
Description
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a null pointer dereference, which would result in a crash and denial of service. The [implementation](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/internal/optimized/optimized_ops.h#L268-L285) unconditionally dereferences a pointer. We have patched the issue in GitHub commit 15691e456c7dc9bd6be203b09765b063bf4a380c. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
How to fix CVE-2021-37688
To remediate CVE-2021-37688, upgrade the affected package to a fixed version below.
- —upgrade to 2.3.4 or later
- —upgrade to 2.3.4 or later
- —upgrade to 15691e456c7dc9bd6be203b09765b063bf4a380c or later
- —upgrade to 15691e456c7dc9bd6be203b09765b063bf4a380c or later
- —upgrade to 2.5.1 or later
- —upgrade to 15691e456c7dc9bd6be203b09765b063bf4a380c or later
- —upgrade to 2.3.4 or later
Is CVE-2021-37688 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (7)
- >= 2.3.0, < 2.3.4, >= 2.4.0, < 2.4.3, >= 2.5.0, < 2.5.1
- from 0, < 2.3.4
- from 0, < 15691e456c7dc9bd6be203b09765b063bf4a380c | >= 2.3.0, < 2.3.4, >= 2.4.0, < 2.4.3
- from 0, < 15691e456c7dc9bd6be203b09765b063bf4a380c | >= 2.3.0, < 2.3.4, >= 2.4.0, < 2.4.3
- >= 2.5.0, < 2.5.1
- from 0, < 15691e456c7dc9bd6be203b09765b063bf4a380c | >= 2.3.0, < 2.3.4, >= 2.4.0, < 2.4.3
- from 0, < 2.3.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
References (8)
- ADVISORYnvd.nist.gov/vuln/detail/CVE-2021-37688
- WEBgithub.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2021-601.yaml
- WEBgithub.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2021-799.yaml
- WEBgithub.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2021-310.yaml