Out-of-bounds read in TensorFlow - CVE-2021-41212
Published: November 5, 2021 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the shape inference code for tf.ragged.cross when processing crafted input to tf.raw_ops.RaggedCross. A remote attacker can send crafted input to trigger a heap out-of-bounds read to disclose sensitive information.