<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 23:01:12 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-29521 — Segfault in SparseCountSparseOutput</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-29521</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&amp;lt;T&amp;gt;` (i.e., `std::vector&amp;lt;absl::flat_hash_map&amp;lt;int64,T&amp;gt;&amp;gt;`(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure. If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`. Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are non-negative) solves this issue. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 and TensorFlow 2.3.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&amp;lt;T&amp;gt;` (i.e., `std::vector&amp;lt;absl::flat_hash_map&amp;lt;int64,T&amp;gt;&amp;gt;`(https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure. If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`. Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are non-negative) solves this issue. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 and TensorFlow 2.3.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-29521</guid>
    </item>
    <item>
      <title>GHSA-hr84-fqvp-48mm — Segfault in SparseCountSparseOutput</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hr84-fqvp-48mm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact
Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken.&lt;/p&gt;
&lt;p&gt;```python
import tensorflow as tf&lt;/p&gt;
&lt;p&gt;indices = tf.constant([], shape=[0, 0], dtype=tf.int64)
values = tf.constant([], shape=[0, 0], dtype=tf.int64)
dense_shape = tf.constant([-100, -100, -100], shape=[3], dtype=tf.int64)
weights = tf.constant([], shape=[0, 0], dtype=tf.int64)&lt;/p&gt;
&lt;p&gt;tf.raw_ops.SparseCountSparseOutput(indices=indices, values=values, dense_shape=dense_shape, weights=weights, minlength=79, maxlength=96, binary_output=False)
```&lt;/p&gt;
&lt;p&gt;This is because the [implementation](https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&amp;lt;T&amp;gt;` (i.e., [`std::vector&amp;lt;absl::flat_hash_map&amp;lt;int64,T&amp;gt;&amp;gt;`](https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure.&lt;/p&gt;
&lt;p&gt;```cc
  bool is_1d = shape.NumElements() == 1;
  int num_batches = is_1d ? 1 : shape.flat&amp;lt;int64&amp;gt;()(0);
  ...
  auto per_batch_counts = BatchedMap&amp;lt;W&amp;gt;(num_batches); 
```&lt;/p&gt;
&lt;p&gt;If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`.
                       
Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact
Specifying a negative dense shape in `tf.raw_ops.SparseCountSparseOutput` results in a segmentation fault being thrown out from the standard library as `std::vector` invariants are broken.&lt;/p&gt;
&lt;p&gt;```python
import tensorflow as tf&lt;/p&gt;
&lt;p&gt;indices = tf.constant([], shape=[0, 0], dtype=tf.int64)
values = tf.constant([], shape=[0, 0], dtype=tf.int64)
dense_shape = tf.constant([-100, -100, -100], shape=[3], dtype=tf.int64)
weights = tf.constant([], shape=[0, 0], dtype=tf.int64)&lt;/p&gt;
&lt;p&gt;tf.raw_ops.SparseCountSparseOutput(indices=indices, values=values, dense_shape=dense_shape, weights=weights, minlength=79, maxlength=96, binary_output=False)
```&lt;/p&gt;
&lt;p&gt;This is because the [implementation](https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L199-L213) assumes the first element of the dense shape is always positive and uses it to initialize a `BatchedMap&amp;lt;T&amp;gt;` (i.e., [`std::vector&amp;lt;absl::flat_hash_map&amp;lt;int64,T&amp;gt;&amp;gt;`](https://github.com/tensorflow/tensorflow/blob/8f7b60ee8c0206a2c99802e3a4d1bb55d2bc0624/tensorflow/core/kernels/count_ops.cc#L27)) data structure.&lt;/p&gt;
&lt;p&gt;```cc
  bool is_1d = shape.NumElements() == 1;
  int num_batches = is_1d ? 1 : shape.flat&amp;lt;int64&amp;gt;()(0);
  ...
  auto per_batch_counts = BatchedMap&amp;lt;W&amp;gt;(num_batches); 
```&lt;/p&gt;
&lt;p&gt;If the `shape` tensor has more than one element, `num_batches` is the first value in `shape`.
                       
Ensuring that the `dense_shape` argument is a valid tensor shape (that is, all elements are…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hr84-fqvp-48mm</guid>
    </item>
  </channel>
</rss>
