Input validation error in TensorFlow - CVE-2021-37674
Published: August 12, 2021 / Updated: May 3, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in tf.raw_ops.MaxPoolGrad when processing crafted orig_input and orig_output tensors. A local user can supply crafted tensor values to cause a denial of service.
The issue can be triggered via a segmentation fault.