Input validation error in TensorFlow - CVE-2021-29591

 

Input validation error in TensorFlow - CVE-2021-29591

Published: May 13, 2021 / Updated: May 4, 2026


Vulnerability identifier: #VU129300
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29591
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the TFLite subgraph evaluation logic when parsing a crafted model with looping subgraphs. A remote attacker can supply a specially crafted model to cause a denial of service.

In certain cases, the infinite loop is replaced by a stack overflow caused by excessive recursive calls. The issue can be triggered when the body and loop subgraphs reference the same subgraph in the While operator.


Affected software

TensorFlow

How to mitigate CVE-2021-29591

Install security update from vendor's website.

TensorFlow - addressed in versions 2.1.4, 2.2.3, 2.3.3, 2.4.2

External References

Related Security Bulletins