Security readout for executives and security teams
Plain-English summary
CVE-2021-29552 is a TensorFlow denial-of-service issue. If an attacker can influence a specific TensorFlow tensor argument, they may cause the process to terminate. The published severity is low because the CVSS vector requires local access, low privileges, high complexity, and only affects availability.
Executive priority
Treat this as a low-priority availability risk unless TensorFlow workloads are multi-tenant or accept untrusted ML inputs. Patch during normal maintenance, but accelerate remediation for shared research platforms, hosted notebooks, or production ML services where a crash could disrupt customer workloads.
Technical view
TensorFlow’s UnsortedSegmentJoin assumed num_segments was a valid scalar. An empty tensor could invalidate an internal CHECK in scalar<T>()(), terminating the process. The issue is classified as CWE-617 and is fixed in TensorFlow 2.5.0 with cherry-picked fixes for supported 2.4.2, 2.3.3, 2.2.3, and 2.1.4 branches.
Likely exposure
Exposure is most plausible in systems running affected TensorFlow versions where local or authenticated users can submit TensorFlow graphs, code, or tensor inputs. Shared notebooks, ML platforms, and batch inference or training jobs deserve review. Ordinary web applications are only exposed if they pass user-controlled data into this operation.
Exploitation context
The source bundle does not identify public exploitation, weaponized tooling, or KEV listing. The impact described is process termination, not data theft or code execution. The CVSS vector indicates local attack, low privileges, high complexity, no user interaction, and low availability impact.
Researcher notes
Focus validation on TensorFlow package versions and reachability of UnsortedSegmentJoin. The vulnerable behavior is a CHECK failure on an empty num_segments tensor, causing termination. Do not assume remote exposure unless the deployment lets an attacker influence TensorFlow execution inputs. KEV is false in the provided bundle.
Mitigation direction
- Upgrade TensorFlow to 2.5.0 or a fixed supported branch release.
- Patch affected branches to 2.4.2, 2.3.3, 2.2.3, or 2.1.4 as applicable.
- Restrict who can submit TensorFlow code, graphs, or arbitrary tensor inputs.
- Check vendor guidance before using unsupported older TensorFlow versions.
- Prioritize shared ML execution environments over isolated developer workstations.
Validation and detection
- Inventory TensorFlow versions in applications, notebooks, containers, and training images.
- Flag versions matching the published vulnerable ranges.
- Identify code paths using UnsortedSegmentJoin with user-influenced tensors.
- Confirm runtime environments use fixed TensorFlow builds.
- Review crash logs for TensorFlow CHECK-failure process terminations.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-617: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-29552 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Low
- CVSS
- 2.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L11.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
2.5LowVector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-jhq9-wm9m-cf89CVE reference · x_refsource_CONFIRM
- https://github.com/tensorflow/tensorflow/commit/704866eabe03a9aeda044ec91a8d0c83fc1ebdbeCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Reachable Assertion
Reachable Assertion represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
