Executive brief
TensorFlow's UnravelIndex operation, used for index manipulation in machine learning models, contains a flaw that allows an attacker to crash applications by providing specially crafted input containing zero values. This causes a denial-of-service condition, making services unavailable until restarted.
Technical details
The vulnerability is a division-by-zero error (CWE-369) in tf.raw_ops.UnravelIndex. The root cause is missing input validation: the operation does not verify that the dims tensor is non-empty or that none of its elements are zero before performing mathematical operations that divide by dim values. An attacker can trigger the flaw by calling UnravelIndex with dims containing a 0 value (e.g., dims=[1,0,2]). No authentication is required; the operation is network-reachable in applications serving TensorFlow models. The impact is denial of service through application crash. Patches are available in TensorFlow 2.3.4, 2.4.3, 2.5.1, and 2.6.0.
Affected products
- Google TensorFlow versions prior to 2.3.4; 2.4.0–2.4.2; 2.5.0
- Google TensorFlow CPU versions prior to 2.3.4; 2.4.0–2.4.2; 2.5.0
- Google TensorFlow GPU versions prior to 2.3.4; 2.4.0–2.4.2; 2.5.0
Timeline
- 2021-08-12: disclosed: NVD publication
- 2021-08-25: advisory: GitHub security advisory published
- 2021-08-12: patched: Fix committed in TensorFlow; patches released in 2.3.4, 2.4.3, 2.5.1, and included in 2.6.0