CVE-2021-41204
Segfault while copying constant resource tensor
5.5
MEDIUM
CVSS 3.1
EPSS 0.02%
Description
TensorFlow is an open source platform for machine learning. In affected versions during TensorFlow's Grappler optimizer phase, constant folding might attempt to deep copy a resource tensor. This results in a segfault, as these tensors are supposed to not change. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
How to fix CVE-2021-41204
To remediate CVE-2021-41204, upgrade the affected package to a fixed version below.
- —upgrade to 2.4.4 or later
- —upgrade to 2.6.1 or later
- —upgrade to 7731e8dfbe4a56773be5dc94d631611211156659 or later
- —upgrade to 7731e8dfbe4a56773be5dc94d631611211156659 or later
- —upgrade to 2.6.1 or later
- —upgrade to 7731e8dfbe4a56773be5dc94d631611211156659 or later
- —upgrade to 2.6.1 or later
Is CVE-2021-41204 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (7)
- from 0, < 2.4.4, >= 2.5.0, < 2.5.2, >= 2.6.0, < 2.6.1
- >= 2.6.0, < 2.6.1
- from 0, < 7731e8dfbe4a56773be5dc94d631611211156659 | from 0, < 2.4.4, >= 2.5.0, < 2.5.2, >= 2.6.0, < 2.6.1, >= 2.7.0rc0, < 2.7.0
- from 0, < 7731e8dfbe4a56773be5dc94d631611211156659 | from 0, < 2.4.4, >= 2.5.0, < 2.5.2, >= 2.6.0, < 2.6.1, >= 2.7.0rc0, < 2.7.0
- >= 2.6.0, < 2.6.1
- from 0, < 7731e8dfbe4a56773be5dc94d631611211156659 | from 0, < 2.4.4, >= 2.5.0, < 2.5.2, >= 2.6.0, < 2.6.1, >= 2.7.0rc0, < 2.7.0
- >= 2.6.0, < 2.6.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |