VDB
KO

PYSEC-2022-144

Details

Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tensor controlled by the user. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit on TensorFlow 2.7.1, TensorFlow 2.6.3, and TensorFlow 2.5.3, as these are also affected and still in supported range.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / tensorflow-gpu
Introduced in: 0 Fixed in: 1361fb7e29449629e1df94d44e0427ebec8c83c7
Fix pip install --upgrade 'tensorflow-gpu>=1361fb7e29449629e1df94d44e0427ebec8c83c7'

References