TensorFlow is an open source platform for machine learning. In affected versions the async implementation of `CollectiveReduceV2` suffers from a memory leak and a use after free. This occurs due to the asynchronous computation and the fact that objects that have been `std::move()`d from are still accessed. The fix will be included in TensorFlow 2.7.0. We will also cherrypick this commit on TensorFlow 2.6.1, as this version is the only one that is also affected.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2021-11-05T22:20:12

Updated: 2021-11-05T22:20:12

Reserved: 2021-09-15T00:00:00


Link: CVE-2021-41220

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-11-05T23:15:08.350

Modified: 2021-11-10T13:16:42.890


Link: CVE-2021-41220

JSON object: View

cve-icon Redhat Information

No data.

CWE