Security readout for executives and security teams
Plain-English summary
CVE-2021-29569 is a low-severity TensorFlow flaw where specially crafted local inputs can make TensorFlow read outside heap-allocated memory. The documented CVSS impact is limited availability loss, with no confidentiality or integrity impact. Business urgency is higher only where untrusted users can run TensorFlow workloads.
Executive priority
Low priority for most organizations, but schedule remediation through normal dependency maintenance. Prioritize faster where shared ML platforms allow low-privileged users to run TensorFlow workloads, because the issue could affect service stability.
Technical view
The issue is CWE-125 in TensorFlow RequantizationRange logic: code assumes input_min and input_max have at least one element and reads element zero. Empty tensors make that read out of bounds. Sources also mention MaxPoolGradWithArgmax, so the public description contains an operation-name inconsistency.
Likely exposure
Affected installations are TensorFlow versions <2.1.4, >=2.2.0 <2.2.3, >=2.3.0 <2.3.3, and >=2.4.0 <2.4.2. Exposure is most relevant in ML notebooks, batch jobs, or services accepting untrusted tensors or user-submitted workloads.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation evidence. CVSS requires local access, low privileges, high attack complexity, and no user interaction. Treat this as a hardening and dependency-update issue unless untrusted local users share TensorFlow execution environments.
Researcher notes
Evidence supports an out-of-bounds heap read caused by empty input_min or input_max tensors. The bundle’s description names MaxPoolGradWithArgmax while the title and linked code reference RequantizationRange; preserve that uncertainty when tracking affected call paths.
Mitigation direction
- Upgrade TensorFlow to 2.5.0 or a fixed supported branch release.
- Use TensorFlow 2.4.2, 2.3.3, 2.2.3, or 2.1.4 where branch pinning is required.
- Restrict untrusted users from submitting arbitrary TensorFlow operations to shared runtimes.
- Check TensorFlow advisory guidance before relying on local workarounds.
Validation and detection
- Inventory TensorFlow package versions across production, notebooks, CI, and ML images.
- Confirm affected version ranges are absent from dependency lockfiles and containers.
- Verify workloads accepting user tensors are isolated from sensitive shared services.
- Review update evidence against the referenced TensorFlow advisory and commit.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-29569 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Low
- CVSS
- 2.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L11.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
2.5LowVector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-3h8m-483j-7xxmCVE reference · x_refsource_CONFIRM
- https://github.com/tensorflow/tensorflow/commit/ef0c008ee84bad91ec6725ddc42091e19a30cf0eCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Out-of-bounds Read
Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
