SCA: security update for tensorflow, tensorflow-cpu, tensorflow-gpu (GHSA-xqfj-35wv-m3cr)

low Tenable Self-Hosted Container Security Plugin ID 420622

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a
dereference of a null pointer in `tf.raw_ops.StringNGrams`. This is because the implementation(https://git
hub.com/tensorflow/tensorflow/blob/1cdd4da14282210cc759e468d9781741ac7d01bf/tensorflow/core/kernels/string
_ngrams_op.cc#L67-L74) does not fully validate the `data_splits` argument. This would result in `ngrams_da
ta`(https://github.com/tensorflow/tensorflow/blob/1cdd4da14282210cc759e468d9781741ac7d01bf/tensorflow/core
/kernels/string_ngrams_op.cc#L106-L110) to be a null pointer when the output would be computed to have 0
or negative size. Later writes to the output tensor would then cause a null pointer dereference. The fix
will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2, TensorFlow
2.3.3, TensorFlow 2.2.3 and TensorFlow 2.1.4, as these are also affected and still in supported range.
(CVE-2021-29541)

See Also

https://github.com/advisories/GHSA-xqfj-35wv-m3cr

Plugin Details

Severity: Low

ID: 420622

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2021-29541

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2

Threat Score: 1.1

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/21/2021

Vulnerability Publication Date: 5/14/2021

Reference Information

CVE: CVE-2021-29541

cwe: CWE-476