rpm package
suse/tensorflow2_2_6_0-gnu-hpc&distro=SUSE Package Hub 15 SP3
pkg:rpm/suse/tensorflow2_2_6_0-gnu-hpc&distro=SUSE%20Package%20Hub%2015%20SP3
Vulnerabilities (63)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-37651 | Hig | 7.1 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.FractionalAvgPoolGrad` can be tricked into accessing data outside of bounds of heap allocated buffers. The [implementation](https://github.com/tensorflow | |
| CVE-2021-37650 | Hig | 7.8 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.ExperimentalDatasetToTFRecord` and `tf.raw_ops.DatasetToTFRecord` can trigger heap buffer overflow and segmentation fault. The [implementation](https://g | |
| CVE-2021-37646 | Med | 5.5 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.StringNGrams` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsigned one and then allocating memory based o | |
| CVE-2021-37645 | Med | 5.5 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsigned one and then allocating | |
| CVE-2021-37644 | Med | 5.5 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the runtime to abort the process due to reallocating a `std::vector` to have a negativ | |
| CVE-2021-37641 | Hig | 7.3 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions if the arguments to `tf.raw_ops.RaggedGather` don't determine a valid ragged tensor code can trigger a read from outside of bounds of heap allocated buffers. The [implementation](https://g | |
| CVE-2021-37635 | Hig | 7.3 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of sparse reduction operations in TensorFlow can trigger accesses outside of bounds of heap allocated data. The [implementation](https://github.com/tensorflow/tensorflow | |
| CVE-2021-37649 | Hig | 7.7 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. The code for `tf.raw_ops.UncompressElement` can be made to trigger a null pointer dereference. The [implementation](https://github.com/tensorflow/tensorflow/blob/f24faa153ad31a4b51578f8181d3aaab77a1ddeb/tensor | |
| CVE-2021-37647 | Hig | 7.7 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. When a user does not supply arguments that determine a valid sparse tensor, `tf.raw_ops.SparseTensorSliceDataset` implementation can be made to dereference a null pointer. The [implementation](https://github.c | |
| CVE-2021-37643 | Hig | 7.7 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. If a user does not provide a valid padding value to `tf.raw_ops.MatrixDiagPartOp`, then the code triggers a null pointer dereference (if input is empty) or produces invalid behavior, ignoring all values after | |
| CVE-2021-37639 | Hig | 8.4 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. When restoring tensors via raw APIs, if the tensor name is not provided, TensorFlow can be tricked into dereferencing a null pointer. Alternatively, attackers can read memory outside the bounds of heap allocat | |
| CVE-2021-37638 | Hig | 7.7 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. Sending invalid argument for `row_partition_types` of `tf.raw_ops.RaggedTensorToTensor` API results in a null pointer dereference and undefined behavior. The [implementation](https://github.com/tensorflow/tens | |
| CVE-2021-37637 | Hig | 7.7 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. It is possible to trigger a null pointer dereference in TensorFlow by passing an invalid input to `tf.raw_ops.CompressElement`. The [implementation](https://github.com/tensorflow/tensorflow/blob/47a06f40411a69 | |
| CVE-2021-37660 | Med | 5.5 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a floating point exception by calling inplace operations with crafted arguments that would result in a division by 0. The [implementation](https://github.com/tensorfl | |
| CVE-2021-37653 | Med | 5.5 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a crash via a floating point exception in `tf.raw_ops.ResourceGather`. The [implementation](https://github.com/tensorflow/tensorflow/blob/f24faa153ad31a4b51578f8181 | |
| CVE-2021-37642 | Med | 5.5 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.ResourceScatterDiv` is vulnerable to a division by 0 error. The [implementation](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e | |
| CVE-2021-37640 | Med | 5.5 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.SparseReshape` can be made to trigger an integral division by 0 exception. The [implementation](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf | |
| CVE-2021-37636 | Med | 5.5 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Aug 12, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.SparseDenseCwiseDiv` is vulnerable to a division by 0 error. The [implementation](https://github.com/tensorflow/tensorflow/blob/a1bc56203f21a5a4995311825f | |
| CVE-2020-26270 | Med | 4.4 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Dec 10, 2020 | In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend. This can result in a query-of-death vulnerability, via denial of service, if users can control the inpu | |
| CVE-2020-26268 | Med | 4.4 | < 2.6.0-bp153.2.3.1 | 2.6.0-bp153.2.3.1 | Dec 10, 2020 | In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memory mapped file which is assumed immutable. However, if the type of the tensor is not an integral type, the operation crashes the Python interpreter as it tries |
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.FractionalAvgPoolGrad` can be tricked into accessing data outside of bounds of heap allocated buffers. The [implementation](https://github.com/tensorflow
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.ExperimentalDatasetToTFRecord` and `tf.raw_ops.DatasetToTFRecord` can trigger heap buffer overflow and segmentation fault. The [implementation](https://g
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.StringNGrams` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsigned one and then allocating memory based o
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsigned one and then allocating
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the runtime to abort the process due to reallocating a `std::vector` to have a negativ
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions if the arguments to `tf.raw_ops.RaggedGather` don't determine a valid ragged tensor code can trigger a read from outside of bounds of heap allocated buffers. The [implementation](https://g
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of sparse reduction operations in TensorFlow can trigger accesses outside of bounds of heap allocated data. The [implementation](https://github.com/tensorflow/tensorflow
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. The code for `tf.raw_ops.UncompressElement` can be made to trigger a null pointer dereference. The [implementation](https://github.com/tensorflow/tensorflow/blob/f24faa153ad31a4b51578f8181d3aaab77a1ddeb/tensor
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. When a user does not supply arguments that determine a valid sparse tensor, `tf.raw_ops.SparseTensorSliceDataset` implementation can be made to dereference a null pointer. The [implementation](https://github.c
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. If a user does not provide a valid padding value to `tf.raw_ops.MatrixDiagPartOp`, then the code triggers a null pointer dereference (if input is empty) or produces invalid behavior, ignoring all values after
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. When restoring tensors via raw APIs, if the tensor name is not provided, TensorFlow can be tricked into dereferencing a null pointer. Alternatively, attackers can read memory outside the bounds of heap allocat
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. Sending invalid argument for `row_partition_types` of `tf.raw_ops.RaggedTensorToTensor` API results in a null pointer dereference and undefined behavior. The [implementation](https://github.com/tensorflow/tens
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. It is possible to trigger a null pointer dereference in TensorFlow by passing an invalid input to `tf.raw_ops.CompressElement`. The [implementation](https://github.com/tensorflow/tensorflow/blob/47a06f40411a69
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a floating point exception by calling inplace operations with crafted arguments that would result in a division by 0. The [implementation](https://github.com/tensorfl
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a crash via a floating point exception in `tf.raw_ops.ResourceGather`. The [implementation](https://github.com/tensorflow/tensorflow/blob/f24faa153ad31a4b51578f8181
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.ResourceScatterDiv` is vulnerable to a division by 0 error. The [implementation](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.SparseReshape` can be made to trigger an integral division by 0 exception. The [implementation](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.SparseDenseCwiseDiv` is vulnerable to a division by 0 error. The [implementation](https://github.com/tensorflow/tensorflow/blob/a1bc56203f21a5a4995311825f
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend. This can result in a query-of-death vulnerability, via denial of service, if users can control the inpu
- affected < 2.6.0-bp153.2.3.1fixed 2.6.0-bp153.2.3.1
In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memory mapped file which is assumed immutable. However, if the type of the tensor is not an integral type, the operation crashes the Python interpreter as it tries
Page 3 of 4