Executive brief
TensorFlow's RequantizationRange operation, used for quantized neural network processing, crashes when given specially crafted empty tensor inputs. An attacker can trigger a heap memory access violation, potentially causing service outages in applications running machine learning inference or training.
Technical details
The vulnerability is a heap out-of-bounds read in the RequantizationRange operation due to missing validation of input tensor dimensions. The vulnerable code assumes input_min and input_max tensors contain at least one element and directly accesses the first element without bounds checking. An attacker can supply empty tensors to trigger an out-of-bounds read. The attack vector is local/programmatic (requires calling the affected TensorFlow API directly). Patches are available in TensorFlow 2.5.0 and backported to 2.4.2, 2.3.3, 2.2.3, and 2.1.4.
Affected products
- Google TensorFlow before 2.1.4, 2.2.0 before 2.2.3, 2.3.0 before 2.3.3, 2.4.0 before 2.4.2
- Google TensorFlow CPU before 2.1.4, 2.2.0 before 2.2.3, 2.3.0 before 2.3.3, 2.4.0 before 2.4.2
- Google TensorFlow GPU before 2.1.4, 2.2.0 before 2.2.3, 2.3.0 before 2.3.3, 2.4.0 before 2.4.2
Timeline
- 2021-05-13: disclosed
- 2021-05-21: patched: Patches released for TensorFlow 2.1.4, 2.2.3, 2.3.3, 2.4.2, and 2.5.0