CVE Vulnerabilities

CVE-2021-29602

Divide By Zero

Published: May 14, 2021 | Modified: May 18, 2021
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

TensorFlow is an end-to-end open source platform for machine learning. The implementation of the DepthwiseConv TFLite operator is vulnerable to a division by zero error(https://github.com/tensorflow/tensorflow/blob/1a8e885b864c818198a5b2c0cbbeca5a1e833bc8/tensorflow/lite/kernels/depthwise_conv.cc#L287-L288). An attacker can craft a model such that inputs fourth dimension would be 0. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.

Weakness

The product divides a value by zero.

Affected Software

Name Vendor Start Version End Version
Tensorflow Google * 2.1.4 (excluding)
Tensorflow Google 2.2.0 (including) 2.2.3 (excluding)
Tensorflow Google 2.3.0 (including) 2.3.3 (excluding)
Tensorflow Google 2.4.0 (including) 2.4.2 (excluding)

References