<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T10:23:41.966150+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tensorflow-2021-29521</id>
    <title>BIT-tensorflow-2021-29521 — Segfault in SparseCountSparseOutput</title>
    <updated>2026-10-09T10:23:42.125104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tensorflow</p>
<p>TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&lt;T&gt;` (i.e., `std::vector&lt;absl::flat_hash_map&lt;int64,T&gt;&gt;`(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure. If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`. Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are non-negative) solves this issue. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 and TensorFlow 2.3.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tensorflow-2021-29521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-46659</id>
    <title>cnvd-2021-46659</title>
    <updated>2026-10-09T10:23:42.125197+00:00</updated>
    <content>cnvd-2021-46659</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-46659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-26440</id>
    <title>EUVD-2026-26440</title>
    <updated>2026-10-09T10:23:42.125219+00:00</updated>
    <content>EUVD-2026-26440</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-26440"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-29521</id>
    <title>fkie_cve-2021-29521</title>
    <updated>2026-10-09T10:23:42.125232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&lt;T&gt;` (i.e., `std::vector&lt;absl::flat_hash_map&lt;int64,T&gt;&gt;`(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure. If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`. Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are non-negative) solves this issue. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 and TensorFlow 2.3.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-29521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hr84-fqvp-48mm</id>
    <title>GHSA-hr84-fqvp-48mm — Segfault in SparseCountSparseOutput</title>
    <updated>2026-10-09T10:23:42.125261+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu</p>
<p>### Impact
Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken.</p>
<p>```python
import tensorflow as tf</p>
<p>indices = tf.constant([], shape=[0, 0], dtype=tf.int64)
values = tf.constant([], shape=[0, 0], dtype=tf.int64)
dense_shape = tf.constant([-100, -100, -100], shape=[3], dtype=tf.int64)
weights = tf.constant([], shape=[0, 0], dtype=tf.int64)</p>
<p>tf.raw_ops.SparseCountSparseOutput(indices=indices, values=values, dense_shape=dense_shape, weights=weights, minlength=79, maxlength=96, binary_output=False)
```</p>
<p>This is because the [implementation](https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&lt;T&gt;` (i.e., [`std::vector&lt;absl::flat_hash_map&lt;int64,T&gt;&gt;`](https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure.</p>
<p>```cc
  bool is_1d = shape.NumElements() == 1;
  int num_batches = is_1d ? 1 : shape.flat&lt;int64&gt;()(0);
  ...
  auto per_batch_counts = BatchedMap&lt;W&gt;(num_batches); 
```</p>
<p>If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`.
                       
Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hr84-fqvp-48mm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-29521</id>
    <title>gsd-2021-29521</title>
    <updated>2026-10-09T10:23:42.125315+00:00</updated>
    <content>gsd-2021-29521</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-29521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-158</id>
    <title>PYSEC-2021-158</title>
    <updated>2026-10-09T10:23:42.125328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tensorflow</p>
<p>TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&lt;T&gt;` (i.e., `std::vector&lt;absl::flat_hash_map&lt;int64,T&gt;&gt;`(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure. If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`. Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are non-negative) solves this issue. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 and TensorFlow 2.3.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-158"/>
  </entry>
</feed>
