Use of Uninitialized Variable in TensorFlow - CVE-2021-41225
Published: November 5, 2021 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of uninitialized value in Grappler optimizer auto_parallel.cc when optimizing a saved model. A remote attacker can supply a crafted saved model without a Dequeue node in the train_nodes vector to cause a denial of service.