-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| tensorflow | pip | < 2.6.4 | 2.6.4 |
| tensorflow | pip | >= 2.7.0, < 2.7.2 | 2.7.2 |
| tensorflow | pip | >= 2.8.0, < 2.8.1 | 2.8.1 |
| tensorflow-cpu | pip | < 2.6.4 | 2.6.4 |
| tensorflow-cpu | pip | >= 2.7.0, < 2.7.2 | 2.7.2 |
| tensorflow-cpu | pip | >= 2.8.0, < 2.8.1 | 2.8.1 |
| tensorflow-gpu | pip | < 2.6.4 | 2.6.4 |
| tensorflow-gpu | pip | >= 2.7.0, < 2.7.2 | 2.7.2 |
| tensorflow-gpu | pip | >= 2.8.0, < 2.8.1 | 2.8.1 |
The vulnerability stems from the missing validation of the 'serialized_summary_metadata' input in TensorSummaryV2's implementation. The C++ code in summary_tensor_op.cc's Compute method for SummaryTensorOpV2 accesses input(2) as a scalar without verifying its shape. The patch explicitly adds an OP_REQUIRES check for scalar shape, confirming this was the missing validation. The function's direct interaction with untrusted input and the crash mechanism described in the vulnerability report align precisely with this code path.
Ongoing coverage of React2Shell