Security readout for executives and security teams
Plain-English summary
This is a low-severity TensorFlow flaw that can cause undefined behavior when a specific random-number operation receives an empty shape input. The documented impact is limited availability loss, not data theft or privilege escalation. It matters most for systems that let untrusted users influence TensorFlow operations or model inputs.
Executive priority
Treat this as routine patching unless affected TensorFlow workloads process untrusted model inputs or run in shared environments. It does not warrant emergency response based on the provided evidence.
Technical view
`tf.raw_ops.ParameterizedTruncatedNormal` failed to validate `shape` before reading its first element. An empty `shape` makes `shape_tensor.flat<T>()` empty, causing a reference binding to a null pointer. The listed affected TensorFlow branches were fixed in 2.5.0 and supported patch releases.
Likely exposure
Exposure is limited to applications using affected TensorFlow versions and reachable code paths invoking `ParameterizedTruncatedNormal` with attacker-influenced shape data. The CVSS vector requires local access, low privileges, high complexity, and has only low availability impact.
Exploitation context
The source bundle does not identify active exploitation, and KEV status is false. Exploitation requires a crafted condition in a specific TensorFlow operation, with no cited confidentiality or integrity impact.
Researcher notes
The root cause is missing input validation before accessing `shape[0]`. The documented fix is in TensorFlow commit `5e52ef5a461570cfb68f3bdbbebfe972cb4e0fd8`; avoid claiming broader impact without additional evidence.
Mitigation direction
- Upgrade TensorFlow to 2.5.0 or a listed patched supported branch.
- Use TensorFlow 2.4.2, 2.3.3, 2.2.3, or 2.1.4 where applicable.
- Inventory pinned TensorFlow dependencies in applications, notebooks, images, and ML pipelines.
- Restrict untrusted control over TensorFlow graph construction or tensor shape inputs until patched.
- Check the TensorFlow advisory before changing unsupported legacy deployments.
Validation and detection
- Confirm deployed TensorFlow versions are outside the affected ranges.
- Review dependency lockfiles and container images for vulnerable TensorFlow packages.
- Identify code paths using `tf.raw_ops.ParameterizedTruncatedNormal` or wrappers around it.
- Check crash telemetry for failures around this operation before and after upgrade.
- Run existing ML application tests after upgrading TensorFlow.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-824: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-29568 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Low
- CVSS
- 2.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L11.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
2.5LowVector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-4p4p-www8-8fv9CVE reference · x_refsource_CONFIRM
- https://github.com/tensorflow/tensorflow/commit/5e52ef5a461570cfb68f3bdbbebfe972cb4e0fd8CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Access of Uninitialized Pointer
Access of Uninitialized Pointer represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
