Out-of-bounds write in TensorFlow - CVE-2021-29614

 

Out-of-bounds write in TensorFlow - CVE-2021-29614

Published: May 13, 2021 / Updated: May 4, 2026


Vulnerability identifier: #VU129278
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-29614
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
TensorFlow
Software vendor:
TensorFlow

Description

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to out-of-bounds write in tf.io.decode_raw when processing input with fixed_length and wider datatypes. A local user can supply specially crafted input to cause a denial of service.

The issue stems from incorrect pointer arithmetic in the padded raw decoding implementation, which can also produce incorrect decoding results.


Remediation

Install security update from vendor's website.

External links