CVE-2021-41221 - log back

CVE-2021-41221 created at 06 Nov 2021 00:12:35
Severity
+ High
Remote
+ Local
Type
+ Arbitrary code execution
Description
+ In TensorFlow before version 2.6.1, the shape inference code for the Cudnn* operations in TensorFlow can be tricked into accessing invalid memory, via a heap buffer overflow. This occurs because the ranks of the input, input_h and input_c parameters are not validated, but code assumes they have certain values.
References
+ https://github.com/tensorflow/tensorflow/security/advisories/GHSA-cqv6-3phm-hcwx
+ https://github.com/tensorflow/tensorflow/commit/af5fcebb37c8b5d71c237f4e59c6477015c78ce6
Notes