Input validation error in TensorFlow - CVE-2021-37677
Published: August 12, 2021 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in shape inference for tf.raw_ops.Dequantize when processing invalid arguments. A remote attacker can supply crafted input values, including an invalid axis value, to cause a denial of service.
The issue can trigger a segfault.