Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Google TensorFlow 存在资源管理错误漏洞,该漏洞源于 CollectiveReduceV2 的异步实现存在内存泄漏和释放后使用问题。 发生这种情况是由于异步计算以及仍然访问了来自 的对象这一事实。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | >= 2.6.0, < 2.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-41208 | 8.8 HIGH | Incomplete validation in boosted trees code |
| CVE-2021-41221 | 7.8 HIGH | Access to invalid memory during shape inference in `Cudnn*` ops |
| CVE-2021-41214 | 7.8 HIGH | Reference binding to `nullptr` in `tf.ragged.cross` |
| CVE-2021-41219 | 7.8 HIGH | Undefined behavior via `nullptr` reference binding in sparse matrix multiplication |
| CVE-2021-41201 | 7.8 HIGH | Unitialized access in `EinsumHelper::ParseEquation` |
| CVE-2021-41203 | 7.8 HIGH | Missing validation during checkpoint loading |
| CVE-2021-41228 | 7.5 HIGH | Code injection in `saved_model_cli` |
| CVE-2021-41224 | 7.1 HIGH | `SparseFillEmptyRows` heap OOB read |
| CVE-2021-41223 | 7.1 HIGH | Heap OOB read in `FusedBatchNorm` kernels |
| CVE-2021-41226 | 7.1 HIGH | Heap OOB read in `SparseBinCount` |
| CVE-2021-41212 | 7.1 HIGH | Heap OOB read in `tf.ragged.cross` |
| CVE-2021-41211 | 7.1 HIGH | Heap OOB read in shape inference for `QuantizeV2` |
| CVE-2021-41205 | 7.1 HIGH | Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops |
| CVE-2021-41210 | 7.1 HIGH | Heap OOB read in `tf.raw_ops.SparseCountSparseOutput` |
| CVE-2021-41206 | 7.0 HIGH | Incomplete validation of shapes in multiple TF ops |
| CVE-2021-41227 | 6.6 MEDIUM | Arbitrary memory read in `ImmutableConst` |
| CVE-2021-41200 | 5.5 MEDIUM | Incomplete validation in `tf.summary.create_file_writer` |
| CVE-2021-41197 | 5.5 MEDIUM | Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes |
| CVE-2021-41198 | 5.5 MEDIUM | Overflow/crash in `tf.tile` when tiling tensor is large |
| CVE-2021-41199 | 5.5 MEDIUM | Overflow/crash in `tf.image.resize` when size is large |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet