
Cloud Vulnerability DB
A community-led vulnerabilities database
TensorFlow, an end-to-end open source platform for machine learning, was found to contain a vulnerability (CVE-2021-29572) related to the implementation of tf.raw_ops.SdcaOptimizer. The vulnerability was discovered in May 2021 and affected versions prior to 2.5.0. The issue was identified by Ying Wang and Yakun Zhang of Baidu X-Team (GitHub Advisory).
The vulnerability stems from the implementation of tf.raw_ops.SdcaOptimizer which triggers undefined behavior due to dereferencing a null pointer. The issue occurs because the implementation does not validate that the user-supplied arguments satisfy all constraints expected by the operation. The vulnerability received a CVSS v3.1 score of 5.5 MEDIUM (NVD).
When exploited, this vulnerability could lead to undefined behavior in applications using the affected TensorFlow versions. The primary risk is associated with the dereferencing of null pointers, which could potentially cause application crashes or unpredictable behavior.
The issue was patched in multiple versions: TensorFlow 2.5.0, 2.4.2, 2.3.3, 2.2.3, and 2.1.4. The fix was implemented in GitHub commit f7cc8755ac6683131fdfa7a8a121f9d7a9dec6fb, which added several missing validations in SDCA. Users are advised to upgrade to the patched versions (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."