Input validation error in TensorFlow - CVE-2021-29608
Published: May 13, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in tf.raw_ops.RaggedTensorToTensor when processing empty input arguments. A local user can supply crafted empty tensors to cause a denial of service.
The issue can manifest as a heap out-of-bounds access or a null pointer dereference in release builds because the relevant DCHECK validations are not enforced there.