<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 19:55:49 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-29544 — CHECK-fail in `QuantizeAndDequantizeV4Grad`</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-29544</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`. This is because the implementation does not validate the rank of the `input_*` tensors. In turn, this results in the tensors being passes as they are to `QuantizeAndDequantizePerChannelGradientImpl`. However, the `vec&amp;lt;T&amp;gt;` method, requires the rank to 1 and triggers a `CHECK` failure otherwise. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 as this is the only other affected version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`. This is because the implementation does not validate the rank of the `input_*` tensors. In turn, this results in the tensors being passes as they are to `QuantizeAndDequantizePerChannelGradientImpl`. However, the `vec&amp;lt;T&amp;gt;` method, requires the rank to 1 and triggers a `CHECK` failure otherwise. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 as this is the only other affected version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-29544</guid>
    </item>
    <item>
      <title>GHSA-6g85-3hm8-83f9 — CHECK-fail in `QuantizeAndDequantizeV4Grad`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6g85-3hm8-83f9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact
An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`:&lt;/p&gt;
&lt;p&gt;```python
import tensorflow as tf&lt;/p&gt;
&lt;p&gt;gradient_tensor = tf.constant([0.0], shape=[1])
input_tensor = tf.constant([0.0], shape=[1])
input_min = tf.constant([[0.0]], shape=[1, 1])
input_max = tf.constant([[0.0]], shape=[1, 1])&lt;/p&gt;
&lt;p&gt;tf.raw_ops.QuantizeAndDequantizeV4Grad(
  gradients=gradient_tensor, input=input_tensor,
  input_min=input_min, input_max=input_max, axis=0)
```                     
                        
This is because the [implementation](https://github.com/tensorflow/tensorflow/blob/95078c145b5a7a43ee046144005f733092756ab5/tensorflow/core/kernels/quantize_and_dequantize_op.cc#L162-L163) does not validate the rank of the `input_*` tensors. In turn, this results in the tensors being passes as they are to [`QuantizeAndDequantizePerChannelGradientImpl`](https://github.com/tensorflow/tensorflow/blob/95078c145b5a7a43ee046144005f733092756ab5/tensorflow/core/kernels/quantize_and_dequantize_op.h#L295-L306):&lt;/p&gt;
&lt;p&gt;```cc 
template &amp;lt;typename Device, typename T&amp;gt;
struct QuantizeAndDequantizePerChannelGradientImpl {
  static void Compute(const Device&amp;amp; d,
                      typename TTypes&amp;lt;T, 3&amp;gt;::ConstTensor gradient,
                      typename TTypes&amp;lt;T, 3&amp;gt;::ConstTensor input,
                      const Tensor* input_min_tensor,
                      const Tensor* input_max_tensor,
                      typename TTypes&amp;lt;T, 3&amp;gt;::Tensor input_backprop,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact
An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`:&lt;/p&gt;
&lt;p&gt;```python
import tensorflow as tf&lt;/p&gt;
&lt;p&gt;gradient_tensor = tf.constant([0.0], shape=[1])
input_tensor = tf.constant([0.0], shape=[1])
input_min = tf.constant([[0.0]], shape=[1, 1])
input_max = tf.constant([[0.0]], shape=[1, 1])&lt;/p&gt;
&lt;p&gt;tf.raw_ops.QuantizeAndDequantizeV4Grad(
  gradients=gradient_tensor, input=input_tensor,
  input_min=input_min, input_max=input_max, axis=0)
```                     
                        
This is because the [implementation](https://github.com/tensorflow/tensorflow/blob/95078c145b5a7a43ee046144005f733092756ab5/tensorflow/core/kernels/quantize_and_dequantize_op.cc#L162-L163) does not validate the rank of the `input_*` tensors. In turn, this results in the tensors being passes as they are to [`QuantizeAndDequantizePerChannelGradientImpl`](https://github.com/tensorflow/tensorflow/blob/95078c145b5a7a43ee046144005f733092756ab5/tensorflow/core/kernels/quantize_and_dequantize_op.h#L295-L306):&lt;/p&gt;
&lt;p&gt;```cc 
template &amp;lt;typename Device, typename T&amp;gt;
struct QuantizeAndDequantizePerChannelGradientImpl {
  static void Compute(const Device&amp;amp; d,
                      typename TTypes&amp;lt;T, 3&amp;gt;::ConstTensor gradient,
                      typename TTypes&amp;lt;T, 3&amp;gt;::ConstTensor input,
                      const Tensor* input_min_tensor,
                      const Tensor* input_max_tensor,
                      typename TTypes&amp;lt;T, 3&amp;gt;::Tensor input_backprop,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6g85-3hm8-83f9</guid>
    </item>
  </channel>
</rss>
