<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:36:28 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-41211 — Heap OOB read in shape inference for `QuantizeV2`</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-41211</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `QuantizeV2` can trigger a read outside of bounds of heap allocated array. This occurs whenever `axis` is a negative value less than `-1`. In this case, we are accessing data before the start of a heap buffer. The code allows `axis` to be an optional argument (`s` would contain an `error::NOT_FOUND` error code). Otherwise, it assumes that `axis` is a valid index into the dimensions of the `input` tensor. If `axis` is less than `-1` then this results in a heap OOB read. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, as this version is the only one that is also affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `QuantizeV2` can trigger a read outside of bounds of heap allocated array. This occurs whenever `axis` is a negative value less than `-1`. In this case, we are accessing data before the start of a heap buffer. The code allows `axis` to be an optional argument (`s` would contain an `error::NOT_FOUND` error code). Otherwise, it assumes that `axis` is a valid index into the dimensions of the `input` tensor. If `axis` is less than `-1` then this results in a heap OOB read. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, as this version is the only one that is also affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-41211</guid>
    </item>
    <item>
      <title>GHSA-cvgx-3v3q-m36c — Heap OOB in shape inference for `QuantizeV2`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cvgx-3v3q-m36c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact
The [shape inference code for `QuantizeV2`](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e22c14f5f49698/tensorflow/core/framework/common_shape_fns.cc#L2509-L2530) can trigger a read outside of bounds of heap allocated array:&lt;/p&gt;
&lt;p&gt;```python
import tensorflow as tf&lt;/p&gt;
&lt;p&gt;@tf.function
def test():
  data=tf.raw_ops.QuantizeV2(
    input=[1.0,1.0],
    min_range=[1.0,10.0],
    max_range=[1.0,10.0],
    T=tf.qint32,
    mode=&amp;#39;MIN_COMBINED&amp;#39;,
    round_mode=&amp;#39;HALF_TO_EVEN&amp;#39;,
    narrow_range=False,
    axis=-100,
    ensure_minimum_range=10)
  return data&lt;/p&gt;
&lt;p&gt;test()
```&lt;/p&gt;
&lt;p&gt;This occurs whenever `axis` is a negative value less than `-1`. In this case, we are accessing data before the start of a heap buffer:
    
```cc
int axis = -1;
Status s = c-&amp;gt;GetAttr(&amp;#34;axis&amp;#34;, &amp;amp;axis);
if (!s.ok() &amp;amp;&amp;amp; s.code() != error::NOT_FOUND) {
  return s;
}   
... 
if (axis != -1) {
  ...
  TF_RETURN_IF_ERROR(
      c-&amp;gt;Merge(c-&amp;gt;Dim(minmax, 0), c-&amp;gt;Dim(input, axis), &amp;amp;depth));
}
```&lt;/p&gt;
&lt;p&gt;The code allows `axis` to be an optional argument (`s` would contain an `error::NOT_FOUND` error code). Otherwise, it assumes that `axis` is a valid index into the dimensions of the `input` tensor. If `axis` is less than `-1` then this results in a heap OOB read.
    
### Patches
We have patched the issue in GitHub commit [a0d64445116c43cf46a5666bd4eee28e7a82f244](https://github.com/tensorflow/tensorflow/commit/a0d64445116c43cf46a5666bd4eee28e7a82f244).
    
The fix will be included in TensorFlow 2.7.0. We will a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact
The [shape inference code for `QuantizeV2`](https://github.com/tensorflow/tensorflow/blob/8d72537c6abf5a44103b57b9c2e22c14f5f49698/tensorflow/core/framework/common_shape_fns.cc#L2509-L2530) can trigger a read outside of bounds of heap allocated array:&lt;/p&gt;
&lt;p&gt;```python
import tensorflow as tf&lt;/p&gt;
&lt;p&gt;@tf.function
def test():
  data=tf.raw_ops.QuantizeV2(
    input=[1.0,1.0],
    min_range=[1.0,10.0],
    max_range=[1.0,10.0],
    T=tf.qint32,
    mode=&amp;#39;MIN_COMBINED&amp;#39;,
    round_mode=&amp;#39;HALF_TO_EVEN&amp;#39;,
    narrow_range=False,
    axis=-100,
    ensure_minimum_range=10)
  return data&lt;/p&gt;
&lt;p&gt;test()
```&lt;/p&gt;
&lt;p&gt;This occurs whenever `axis` is a negative value less than `-1`. In this case, we are accessing data before the start of a heap buffer:
    
```cc
int axis = -1;
Status s = c-&amp;gt;GetAttr(&amp;#34;axis&amp;#34;, &amp;amp;axis);
if (!s.ok() &amp;amp;&amp;amp; s.code() != error::NOT_FOUND) {
  return s;
}   
... 
if (axis != -1) {
  ...
  TF_RETURN_IF_ERROR(
      c-&amp;gt;Merge(c-&amp;gt;Dim(minmax, 0), c-&amp;gt;Dim(input, axis), &amp;amp;depth));
}
```&lt;/p&gt;
&lt;p&gt;The code allows `axis` to be an optional argument (`s` would contain an `error::NOT_FOUND` error code). Otherwise, it assumes that `axis` is a valid index into the dimensions of the `input` tensor. If `axis` is less than `-1` then this results in a heap OOB read.
    
### Patches
We have patched the issue in GitHub commit [a0d64445116c43cf46a5666bd4eee28e7a82f244](https://github.com/tensorflow/tensorflow/commit/a0d64445116c43cf46a5666bd4eee28e7a82f244).
    
The fix will be included in TensorFlow 2.7.0. We will a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cvgx-3v3q-m36c</guid>
    </item>
  </channel>
</rss>
