Junglewise Threat Intelligence

CVE-2021-29523: PYSEC-2021-649 - TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf

CVE-2021-29523 · Severity: low · CVSS 3.1 · Published 2021-05-14

Technologies: tensorflow (PyPI), tensorflow-cpu (PyPI), Google TensorFlow, tensorflow-gpu (PyPI). Vendors: PyPI, Google.

Executive brief

TensorFlow's AddManySparseToTensorsMap operation processes sparse tensor data. An attacker can crash a TensorFlow application by providing specially crafted tensor dimension values that cause an integer overflow, triggering a denial-of-service condition without authentication required.

Technical details

The vulnerability is an integer overflow (CWE-190) in the AddManySparseToTensorsMap operation's TensorShape constructor. The vulnerable code uses a legacy TensorShape constructor that invokes a CHECK operation on the InitDims method without proper overflow validation. When an attacker provides dimension values in the sparse_shape parameter that cause multiplication overflow during tensor shape initialization, the CHECK fails and terminates the process. The vulnerability requires local access (or network access if the application exposes this operation) and no authentication. A fix using BuildTensorShapeBase or AddDimWithStatus to handle overflow gracefully was committed and included in TensorFlow 2.5.0, with backports to 2.4.2, 2.3.3, 2.2.3, and 2.1.4.

Affected products

  • Google TensorFlow 0.x, 1.x, 2.0.0–2.1.3, 2.2.0–2.2.2, 2.3.0–2.3.2, 2.4.0–2.4.1

Timeline

  • 2021-05-13: disclosed
  • 2021-05-21: patched: Fix included in TensorFlow 2.5.0 and backported to 2.4.2, 2.3.3, 2.2.3, 2.1.4

References

Related threats