CVE-2021-41222

Segfault due to negative splits in `SplitV`

TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trigger a segfault is an attacker supplies negative arguments. This occurs whenever `size_splits` contains more than one value and at least one value is negative. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, TensorFlow 2.5.2, and TensorFlow 2.4.4, as these are also affected and still in supported range.


We have discovered 59 live websites that are affected by CVE-2021-41222.

Run a Free Instant Scan




Affected Software

Product  tensorflow
Category Animation
Vulnerable Domains59 live websites (100% of tensorflow install base)
Vulnerable Versions
  • from 0 through 2.4.4
  • from 2.5 through 2.5.2
  • from 2.6 through 2.6.1
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-682 Incorrect Calculation



Details

  • Published - Nov 6, 2021
  • Updated - Aug 4, 2024

Website Distribution by Country

Number of websites using CVE-2021-41222
United States44 websites



Germany4 websites
India2 websites
Netherlands2 websites
Austria1 websites
Chile1 websites
Cyprus1 websites
Denmark1 websites
Greece1 websites
Korea, South1 websites

Website Distribution by TLD

Number of websites using CVE-2021-41222
.com27 websites
.net2 websites
.org2 websites
.at1 websites
.ch1 websites
.de1 websites
.dk1 websites
.io1 websites

Websites affected by CVE-2021-41222

Top websites that are affected by CVE-2021-41222. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States***,***
*******.************.de Germany***,***
******.me United States*,***,***
***********.com United States*,***,***
************.com United States*,***,***
***********.com United States*,***,***
*******.**.kr Korea, South*,***,***
**********.com Netherlands*,***,***
*********.******.**********.org Germany*,***,***
***********.com United States*,***,***
See full domain list

FAQ

CVE-2021-41222 is Incorrect Calculation in tensorflow
A total of 59 websites have been identified as vulnerable to CVE-2021-41222, based on global website indexing conducted by WebTechSurvey.
The tensorflow is affected by the CVE-2021-41222 vulnerability.
tensorflow versions up to 2.6.1 are vulnerable to CVE-2021-41222.
CVE-2021-41222 is resolved in version 2.6.1 of tensorflow.