<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T23:01:11.577688+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2021-29521</id>
    <title>CVE-2021-29521 — Segfault in SparseCountSparseOutput</title>
    <updated>2026-10-09T23:01:11.579914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> tensorflow</p>
<p>TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&lt;T&gt;` (i.e., `std::vector&lt;absl::flat_hash_map&lt;int64,T&gt;&gt;`(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure. If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`. Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are non-negative) solves this issue. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 and TensorFlow 2.3.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2021-29521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hr84-fqvp-48mm</id>
    <title>GHSA-hr84-fqvp-48mm — Segfault in SparseCountSparseOutput</title>
    <updated>2026-10-09T23:01:11.579989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu</p>
<p>### Impact
Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken.</p>
<p>```python
import tensorflow as tf</p>
<p>indices = tf.constant([], shape=[0, 0], dtype=tf.int64)
values = tf.constant([], shape=[0, 0], dtype=tf.int64)
dense_shape = tf.constant([-100, -100, -100], shape=[3], dtype=tf.int64)
weights = tf.constant([], shape=[0, 0], dtype=tf.int64)</p>
<p>tf.raw_ops.SparseCountSparseOutput(indices=indices, values=values, dense_shape=dense_shape, weights=weights, minlength=79, maxlength=96, binary_output=False)
```</p>
<p>This is because the [implementation](https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&lt;T&gt;` (i.e., [`std::vector&lt;absl::flat_hash_map&lt;int64,T&gt;&gt;`](https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure.</p>
<p>```cc
  bool is_1d = shape.NumElements() == 1;
  int num_batches = is_1d ? 1 : shape.flat&lt;int64&gt;()(0);
  ...
  auto per_batch_counts = BatchedMap&lt;W&gt;(num_batches); 
```</p>
<p>If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`.
                       
Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hr84-fqvp-48mm"/>
  </entry>
</feed>
