NULL pointer dereference in TensorFlow - CVE-2021-37643
Published: August 12, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in MatrixDiagPartOp when processing an invalid padding_value tensor. A local user can provide an empty padding_value input to cause a denial of service.
All versions of the operation are affected, including MatrixDiagPartV2.