Описание
TensorFlow is an open source platform for machine learning. In affected versions the Keras pooling layers can trigger a segfault if the size of the pool is 0 or if a dimension is negative. This is due to the TensorFlow's implementation of pooling operations where the values in the sliding window are not checked to be strictly positive. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.4.4 (исключая)Версия от 2.5.0 (включая) до 2.5.2 (исключая)Версия от 2.6.0 (включая) до 2.6.1 (исключая)
Одно из
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00049
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-191
CWE-191
Связанные уязвимости
CVSS3: 5.5
debian
больше 4 лет назад
TensorFlow is an open source platform for machine learning. In affecte ...
CVSS3: 5.5
github
около 4 лет назад
Crash in `max_pool3d` when size argument is 0 or negative
EPSS
Процентиль: 15%
0.00049
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-191
CWE-191