MindSpore is a machine-learning framework maintained as a niche but strategically positioned component in AI/ML development toolchains, with its disclosed vulnerabilities concentrating in the core framework product. The recurring exposure centers on memory-safety and arithmetic issues—divide-by-zero conditions, out-of-bounds reads and writes, and improper memory-buffer restrictions—that are characteristic of numeric-heavy deep-learning kernels and tensor-manipulation primitives. Current severity, exploitation, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mindspore over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33653HIGH When performing the derivation shape operation of the SpaceToBatch operator, if there is a value of 0 in the parameter block_shape element, it will cause a division by 0 exception. | Jun 27, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-33652HIGH When the Reduce operator run operation is executed, if there is a value of 0 in the parameter axis_sizes element, it will cause a division by 0 exception. | Jun 27, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-33651HIGH When performing the analytical operation of the DepthwiseConv2D operator, if the attribute depth_multiplier is 0, it will cause a division by 0 exception. | Jun 27, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-33650HIGH When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three, it will access data outside of bounds of inputs which alloc | Jun 27, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-33649HIGH When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater than or equal to the size of the input_shape, it will access da | Jun 27, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-33648HIGH When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside | Jun 27, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-33654HIGH When performing the initialization operation of the Split operator, if a dimension in the input shape is 0, it will cause a division by 0 exception. | Jun 27, 2022 | 7.5 | 23 | NO | NO |
CVE-2021-33647HIGH When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will access data outside of bounds of heap allocated buffers. | Jun 27, 2022 | 7.5 | 23 | NO | NO |
CVE-2023-2970MEDIUM A vulnerability classified as problematic was found in MindSpore 2.0.0-alpha/2.0.0-rc1. This vulnerability affects the function JsonHelper::UpdateArray of the file mindspore/ccsrc/ | May 30, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mindspore.
Media articles that mention a CVE ID that affects a product developed by Mindspore — matched by CVE ID, not by vendor name.