Out-of-bounds write in TensorFlow - CVE-2021-29614
Published: May 13, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in tf.io.decode_raw when processing input with fixed_length and wider datatypes. A local user can supply specially crafted input to cause a denial of service.
The issue stems from incorrect pointer arithmetic in the padded raw decoding implementation, which can also produce incorrect decoding results.