Heap-based buffer overflow in TensorFlow - CVE-2021-41221
Published: November 5, 2021 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in the shape inference code for Cudnn* operations when processing crafted input tensors. A remote attacker can supply malformed values for the input, input_h, and input_c parameters to cause a denial of service.
The issue occurs because the ranks of these parameters are not validated before the code assumes specific dimensions.