"value":"TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.SparseDenseCwiseMul`, an attacker can trigger denial of service via `CHECK`-fails or accesses to outside the bounds of heap allocated data. Since the implementation(https://github.com/tensorflow/tensorflow/blob/38178a2f7a681a7835bb0912702a134bfe3b4d84/tensorflow/core/kernels/sparse_dense_binary_op_shared.cc#L68-L80) only validates the rank of the input arguments but no constraints between dimensions(https://www.tensorflow.org/api_docs/python/tf/raw_ops/SparseDenseCwiseMul), an attacker can abuse them to trigger internal `CHECK` assertions (and cause program termination, denial of service) or to write to memory outside of bounds of heap allocated tensor buffers. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow 2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range."
},
{
"lang":"es",
"value":"TensorFlow es una plataforma de c\u00f3digo abierto de extremo a extremo para el aprendizaje autom\u00e1tico. Debido a una falta de comprobaci\u00f3n en \"tf.raw_ops.SparseDenseCwiseMul\", un atacante puede desencadenar una denegaci\u00f3n de servicio por medio de fallos de \"CHECK\" o accesos fuera de l\u00edmites de los datos asignados a la pila. Dado que la implementaci\u00f3n (https://github.com/tensorflow/tensorflow/blob/38178a2f7a681a7835bb0912702a134bfe3b4d84/tensorflow/core/kernels/sparse_dense_binary_op_shared.cc#L68-L80) solo comprueba el rango de los argumentos de entrada (pero sin restricciones) //www.tensorflow.org/api_docs/python/tf/raw_ops/SparseDenseCwiseMul), un atacante puede abusar de ellos para activar aserciones internas \"CHECK\" (y causar la terminaci\u00f3n del programa, denegaci\u00f3n de servicio) o para escribir en una memoria fuera de l\u00edmites de b\u00faferes tensoriales asignados a la pila. La correcci\u00f3n ser\u00e1 incluida en TensorFlow versi\u00f3n 2.5.0"