NULL pointer dereference in TensorFlow - CVE-2021-37647
Published: August 12, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in tf.raw_ops.SparseTensorSliceDataset when processing invalid sparse tensor arguments. A remote user can supply empty indices or mismatched sparse tensor inputs to cause a denial of service.