Heap-based buffer overflow in TensorFlow - CVE-2021-41226
Published: November 5, 2021 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based out-of-bounds write in the SparseBinCount implementation when processing crafted sparse bincount input. A remote attacker can supply malformed values that are not properly validated against the sparse output shape to cause a denial of service.