Out-of-Bounds Affecting tensorflow package, versions [2.5.0,2.5.1) [2.4.0,2.4.3) [,2.3.4)
Threat Intelligence
EPSS
0.04% (14th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-TENSORFLOW-1540818
- published 13 Aug 2021
- disclosed 13 Aug 2021
- credit Unknown
Introduced: 13 Aug 2021
CVE-2021-37635 Open this link in a new tabHow to fix?
Upgrade tensorflow
to version 2.5.1, 2.4.3, 2.3.4 or higher.
Overview
tensorflow is a machine learning framework.
Affected versions of this package are vulnerable to Out-of-Bounds as the implementation of sparse reduction operations in TensorFlow can trigger accesses outside of bounds of heap allocated data. The implementation fails to validate that each reduction group does not overflow and that each corresponding index does not point to outside the bounds of the input tensor.
References
CVSS Scores
version 3.1