Heap-based buffer overflow in TensorFlow - CVE-2021-37650
Published: August 12, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in tf.raw_ops.ExperimentalDatasetToTFRecord and tf.raw_ops.DatasetToTFRecord when processing a dataset containing non-string records. A local user can supply a specially crafted dataset with numeric types to cause a denial of service or execute arbitrary code.