NULL pointer dereference in TensorFlow - CVE-2021-29518
Published: May 13, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in session operations in eager mode when invoking raw session ops. A local user can call GetSessionTensor or DeleteSessionTensor in eager mode to cause a denial of service.
Eager mode is the default in TensorFlow 2.0 and later.