Input validation error in TensorFlow - CVE-2021-29567
Published: May 13, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in tf.raw_ops.SparseDenseCwiseMul when processing crafted sparse and dense tensor inputs with inconsistent dimensions. A remote attacker can send crafted input tensors to cause a denial of service.
The issue can trigger internal CHECK failures or out-of-bounds access to heap-allocated tensor buffers.