{"id":"CVE-2021-29544","aliases":["BIT-tensorflow-2021-29544","GHSA-6g85-3hm8-83f9","PYSEC-2021-181","PYSEC-2021-472","PYSEC-2021-670"],"url":"https://o3.security/vulnerability/CVE-2021-29544","summary":"CHECK-fail in `QuantizeAndDequantizeV4Grad`","details":"TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.QuantizeAndDequantizeV4Grad`. This is because the implementation does not validate the rank of the `input_*` tensors. In turn, this results in the tensors being passes as they are to `QuantizeAndDequantizePerChannelGradientImpl`. However, the `vec<T>` method, requires the rank to 1 and triggers a `CHECK` failure otherwise. The fix will be included in TensorFlow 2.5.0. We will also cherrypick this commit on TensorFlow 2.4.2 as this is the only other affected version.","published":"2021-05-14T20:15:12.623Z","modified":"2026-08-07T16:49:56.178237Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"tensorflow","fixedVersion":"2.4.2"},{"ecosystem":"PyPI","name":"tensorflow-cpu","fixedVersion":"2.4.2"},{"ecosystem":"PyPI","name":"tensorflow-gpu","fixedVersion":"2.4.2"}],"fix":{"url":"https://github.com/tensorflow/tensorflow/commit/20431e9044cf2ad3c0323c34888b192f3289af6b","label":"tensorflow/tensorflow@20431e9"},"references":[{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/blob/95078c145b5a7a43ee046144005f733092756ab5/tensorflow/core/kernels/quantize_and_dequantize_op.cc#L162-L163"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/blob/95078c145b5a7a43ee046144005f733092756ab5/tensorflow/core/kernels/quantize_and_dequantize_op.h#L295-L306"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/20431e9044cf2ad3c0323c34888b192f3289af6b"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6g85-3hm8-83f9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:49:56.178237Z"}}