CVE-2021-37688
HIGHGoogle Tensorflow < 2.3.4 - NULL Pointer Dereference
Title source: ruleDescription
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a null pointer dereference, which would result in a crash and denial of service. The [implementation](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/internal/optimized/optimized_ops.h#L268-L285) unconditionally dereferences a pointer. We have patched the issue in GitHub commit 15691e456c7dc9bd6be203b09765b063bf4a380c. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-vcjj-9vg7-vf68
Patch, Third Party Advisory x_refsource_misc
https://github.com/tensorflow/tensorflow/commit/15691e456c7dc9bd6be203b09765b063bf4a380c
Scores
CVSS v3
7.8
EPSS
0.0005
EPSS Percentile
14.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-476
Status
published
Products (6)
google/tensorflow
2.5.0
google/tensorflow
2.6.0 rc0 (3 CPE variants)
google/tensorflow
2.3.0 - 2.3.4
pypi/tensorflow
0 - 2.3.4PyPI
pypi/tensorflow-cpu
2.5.0 - 2.5.1PyPI
pypi/tensorflow-gpu
0 - 2.3.4PyPI
Published
Aug 12, 2021
Tracked Since
Feb 18, 2026