You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.
Description
TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that use quantization can be made to use unitialized values. [For example](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/lite/kernels/depthwise_conv.cc#L198-L200). The issue stems from the fact that `quantization.params` is only valid if `quantization.type` is different that `kTfLiteNoQuantization`. However, these checks are missing in large parts of the code. We have patched the issue in GitHub commits 537bc7c723439b9194a358f64d871dd326c18887, 4a91f2069f7145aab6ba2d8cfe41be8a110c18a5 and 8933b8a21280696ab119b63263babdb54c298538. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
OR
*cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* versions from (including) 2.3.0 up to (excluding) 2.3.4
*cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* versions from (including) 2.4.0 up to (excluding) 2.4.3
*cpe:2.3:a:google:tensorflow:2.5.0:*:*:*:*:*:*:*
*cpe:2.3:a:google:tensorflow:2.6.0:rc0:*:*:*:*:*:*
*cpe:2.3:a:google:tensorflow:2.6.0:rc1:*:*:*:*:*:*
*cpe:2.3:a:google:tensorflow:2.6.0:rc2:*:*:*:*:*:*
Changed
Reference Type
https://github.com/tensorflow/tensorflow/commit/4a91f2069f7145aab6ba2d8cfe41be8a110c18a5 No Types Assigned
https://github.com/tensorflow/tensorflow/commit/4a91f2069f7145aab6ba2d8cfe41be8a110c18a5 Patch, Third Party Advisory
Changed
Reference Type
https://github.com/tensorflow/tensorflow/commit/537bc7c723439b9194a358f64d871dd326c18887 No Types Assigned
https://github.com/tensorflow/tensorflow/commit/537bc7c723439b9194a358f64d871dd326c18887 Patch, Third Party Advisory
Changed
Reference Type
https://github.com/tensorflow/tensorflow/commit/8933b8a21280696ab119b63263babdb54c298538 No Types Assigned
https://github.com/tensorflow/tensorflow/commit/8933b8a21280696ab119b63263babdb54c298538 Patch, Third Party Advisory
Changed
Reference Type
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-4c4g-crqm-xrxw No Types Assigned
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-4c4g-crqm-xrxw Third Party Advisory
CPE Deprecation Remap by NIST8/17/2021 9:23:09 AM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:a:tensorflow:tensorflow:*:*:*:*:*:*:*:* versions from (including) 2.4.0 from (including) 2.4.3
OR
*cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* versions from (including) 2.4.0 from (including) 2.4.3
CPE Deprecation Remap by NIST8/17/2021 9:23:17 AM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:a:tensorflow:tensorflow:*:*:*:*:*:*:*:* versions from (including) 2.5.0 from (including) 2.5.1
OR
*cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* versions from (including) 2.5.0 from (including) 2.5.1
CPE Deprecation Remap by NIST8/17/2021 9:22:56 AM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:a:tensorflow:tensorflow:*:*:*:*:*:*:*:* versions from (including) 2.3.0 from (including) 2.3.4
OR
*cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:* versions from (including) 2.3.0 from (including) 2.3.4
CPE Deprecation Remap by NIST8/17/2021 9:21:15 AM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:a:tensorflow:tensorflow:2.6.0:rc2:*:*:*:*:*:*
OR
*cpe:2.3:a:google:tensorflow:2.6.0:rc2:*:*:*:*:*:*
CPE Deprecation Remap by NIST8/17/2021 9:21:23 AM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:a:tensorflow:tensorflow:2.6.0:rc1:*:*:*:*:*:*
OR
*cpe:2.3:a:google:tensorflow:2.6.0:rc1:*:*:*:*:*:*
CPE Deprecation Remap by NIST8/17/2021 9:21:35 AM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:a:tensorflow:tensorflow:2.6.0:rc0:*:*:*:*:*:*
OR
*cpe:2.3:a:google:tensorflow:2.6.0:rc0:*:*:*:*:*:*
Quick Info
CVE Dictionary Entry: CVE-2021-37682 NVD
Published Date: 08/12/2021 NVD
Last Modified: 06/17/2026
Source: GitHub, Inc.