Input validation error in TensorFlow - CVE-2021-37661
Published: August 12, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in boosted_trees_create_quantile_stream_resource when processing negative num_streams arguments. A local user can supply a negative num_streams value to cause a denial of service.
The issue is triggered by an integer conversion from a negative signed value to a large unsigned value during memory reservation.