CVE-2021-41221

Access to invalid memory during shape inference in `Cudnn*` ops

TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for the `Cudnn*` operations in TensorFlow can be tricked into accessing invalid memory, via a heap buffer overflow. This occurs because the ranks of the `input`, `input_h` and `input_c` parameters are not validated, but code assumes they have certain values. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.


We have discovered 25 live websites that are affected by CVE-2021-41221.

Run a Free Instant Scan




Affected Software

Product  tensorflow
Category JavaScript Libraries
Vulnerable Domains25 live websites (6.98% of tensorflow install base)
Vulnerable Versions
  • from 0 through 2.4.4
  • from 2.5 through 2.5.2
  • from 2.6 through 2.6.1
Vulnerable Versions Count4 versions ( 57% of all versions)


Common Weakness Enumeration

CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')



Details

  • Published - Nov 5, 2021
  • Updated - Aug 4, 2024

Website Distribution by Country

Number of websites using CVE-2021-41221
United States17 websites



Germany2 websites
India2 websites
Brazil1 websites
Canada1 websites
Korea, South1 websites
Netherlands1 websites

Website Distribution by TLD

Number of websites using CVE-2021-41221
.com14 websites
.net2 websites
.com.br1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-41221

Top websites that are affected by CVE-2021-41221. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States***,***
************.com United States***,***
******.me United States*,***,***
***********.com United States*,***,***
************.com United States*,***,***
****.net United States*,***,***
***********.com United States*,***,***
*******.**.kr Korea, South*,***,***
**********.com Netherlands*,***,***
********.app United States*,***,***
See full domain list

FAQ

CVE-2021-41221 is Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in tensorflow
A total of 25 websites have been identified as vulnerable to CVE-2021-41221, based on global website indexing conducted by WebTechSurvey.
The tensorflow is affected by the CVE-2021-41221 vulnerability.
tensorflow versions up to 2.6.1 are vulnerable to CVE-2021-41221.
CVE-2021-41221 is resolved in version 2.6.1 of tensorflow.