CVE-2021-41197 - log back

CVE-2021-41197 created at 06 Nov 2021 00:12:33
Severity
+ Medium
Remote
+ Local
Type
+ Incorrect calculation
Description
+ A security issue has been found in TensorFlow before version 2.6.1. TensorFlow allows tensor to have a large number of dimensions and each dimension can be as large as desired. However, the total number of elements in a tensor must fit within an int64_t. If an overflow occurs, MultiplyWithoutOverflow would return a negative result. In the majority of TensorFlow codebase this then results in a CHECK-failure. Newer constructs exist which return a Status instead of crashing the binary. This is similar to CVE-2021-29584.
References
+ https://github.com/tensorflow/tensorflow/security/advisories/GHSA-prcg-wp5q-rv7p
+ https://github.com/tensorflow/tensorflow/issues/46890
+ https://github.com/tensorflow/tensorflow/issues/51908
+ https://github.com/tensorflow/tensorflow/commit/a871989d7b6c18cdebf2fb4f0e5c5b62fbc19edf
+ https://github.com/tensorflow/tensorflow/commit/d81b1351da3e8c884ff836b64458d94e4a157c15
+ https://github.com/tensorflow/tensorflow/commit/7c1692bd417eb4f9b33ead749a41166d6080af85
Notes