Google TensorFlow是美国谷歌(Google)公司的一套用于机器学习的端到端开源平台。 Google TensorFlow 存在缓冲区错误漏洞,该漏洞源于 ImmutableConst 操作可以被诱骗读取任意内存内容。 这是因为 TensorFlow 字符串类(tstring)对内存映射字符串有一个特殊情况,但操作本身不提供对这种数据类型的任何支持。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tensorflow | tensorflow | >= 2.6.0, < 2.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-41208 | 8.8 HIGH | Incomplete validation in boosted trees code |
| CVE-2021-41219 | 7.8 HIGH | Undefined behavior via `nullptr` reference binding in sparse matrix multiplication |
| CVE-2021-41220 | 7.8 HIGH | Use after free in `CollectiveReduceV2` |
| CVE-2021-41221 | 7.8 HIGH | Access to invalid memory during shape inference in `Cudnn*` ops |
| CVE-2021-41203 | 7.8 HIGH | Missing validation during checkpoint loading |
| CVE-2021-41201 | 7.8 HIGH | Unitialized access in `EinsumHelper::ParseEquation` |
| CVE-2021-41214 | 7.8 HIGH | Reference binding to `nullptr` in `tf.ragged.cross` |
| CVE-2021-41228 | 7.5 HIGH | Code injection in `saved_model_cli` |
| CVE-2021-41212 | 7.1 HIGH | Heap OOB read in `tf.ragged.cross` |
| CVE-2021-41205 | 7.1 HIGH | Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops |
| CVE-2021-41210 | 7.1 HIGH | Heap OOB read in `tf.raw_ops.SparseCountSparseOutput` |
| CVE-2021-41211 | 7.1 HIGH | Heap OOB read in shape inference for `QuantizeV2` |
| CVE-2021-41226 | 7.1 HIGH | Heap OOB read in `SparseBinCount` |
| CVE-2021-41223 | 7.1 HIGH | Heap OOB read in `FusedBatchNorm` kernels |
| CVE-2021-41224 | 7.1 HIGH | `SparseFillEmptyRows` heap OOB read |
| CVE-2021-41206 | 7.0 HIGH | Incomplete validation of shapes in multiple TF ops |
| CVE-2021-41200 | 5.5 MEDIUM | Incomplete validation in `tf.summary.create_file_writer` |
| CVE-2021-41195 | 5.5 MEDIUM | Crash in `tf.math.segment_*` operations |
| CVE-2021-41197 | 5.5 MEDIUM | Crashes due to overflow and `CHECK`-fail in ops with large tensor shapes |
| CVE-2021-41198 | 5.5 MEDIUM | Overflow/crash in `tf.tile` when tiling tensor is large |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet