Heap-based buffer overflow in TensorFlow - CVE-2021-41223
Published: November 5, 2021 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in FusedBatchNorm kernels when processing crafted input tensors in the FusedBatchNormGrad operation. A remote attacker can supply inconsistent tensor shapes to trigger an out-of-bounds heap access and cause a denial of service.