{"schema_version":"1.8.0","id":"CVE-2021-37674","published":"2021-08-12T23:15:07.970Z","modified":"2026-08-07T16:57:29.255618Z","aliases":["BIT-tensorflow-2021-37674","GHSA-7ghq-fvr3-pj2x","PYSEC-2021-296","PYSEC-2021-587","PYSEC-2021-785"],"related":["openSUSE-SU-2022:10014-1","openSUSE-SU-2024:12116-1"],"details":"TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a segmentation fault in `tf.raw_ops.MaxPoolGrad` caused by missing validation. The [implementation](https://github.com/tensorflow/tensorflow/blob/460e000de3a83278fb00b61a16d161b1964f15f4/tensorflow/core/kernels/maxpooling_op.cc) misses some validation for the `orig_input` and `orig_output` tensors. The fixes for CVE-2021-29579 were incomplete. We have patched the issue in GitHub commit 136b51f10903e044308cf77117c0ed9871350475. The fix will be included in TensorFlow 2.6.0. We will also cherrypick this commit on TensorFlow 2.5.1, TensorFlow 2.4.3, and TensorFlow 2.3.4, as these are also affected and still in supported range.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tensorflow/tensorflow","events":[{"introduced":"b36436b087bd8e8701ef51718179037cccdfc26e"},{"fixed":"7462dcaae1e8cfe1dfd0c62dd6083f9749a9d827"},{"introduced":"582c8d236cb079023657287c318ff26adb239002"},{"fixed":"4c0b84bf2a714bcdd18da1f1f94d533d72399d52"},{"introduced":"a4dfb8d1a71385bd6d122e4f27f86dcebb96712d"},{"last_affected":"5368d50428b30b7c9ccd038aec65d09252d16596"},{"fixed":"136b51f10903e044308cf77117c0ed9871350475"}],"database_specific":{"cpe":["cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.5.0:*:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.6.0:rc0:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.6.0:rc1:*:*:*:*:*:*","cpe:2.3:a:google:tensorflow:2.6.0:rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.3.0"},{"fixed":"2.3.4"},{"introduced":"2.4.0"},{"fixed":"2.4.3"},{"introduced":"2.5.0"},{"last_affected":"2.5.0"},{"introduced":"2.6.0-rc0"},{"last_affected":"2.6.0-rc0"},{"introduced":"2.6.0-rc1"},{"last_affected":"2.6.0-rc1"},{"introduced":"2.6.0-rc2"},{"last_affected":"2.6.0-rc2"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["2.5.0","2.6.0-rc0","2.6.0-rc1","2.6.0-rc2","v2.3.3","v2.4.2","v2.3.2","v2.4.1","v2.4.0","v2.3.1","v2.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37674.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"31570609277633401106222256452068387691","length":4202},"id":"CVE-2021-37674-263449d6","signature_type":"Function","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/136b51f10903e044308cf77117c0ed9871350475","target":{"file":"tensorflow/core/kernels/maxpooling_op.cc","function":"SpatialMaxPoolWithArgMaxHelper"}},{"deprecated":false,"digest":{"function_hash":"29276202328383850718060768810697803666","length":2530},"id":"CVE-2021-37674-806c790a","signature_type":"Function","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/136b51f10903e044308cf77117c0ed9871350475","target":{"file":"tensorflow/core/kernels/pooling_ops_common.cc","function":"PoolParameters::PoolParameters"}},{"deprecated":false,"digest":{"line_hashes":["300545745172636759101116666692124250052","136334434737533024159090578033901353510","184429245809884864649767382928212710591","49456323497966006715979208064567184416"],"threshold":0.9},"id":"CVE-2021-37674-cf1fa930","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/136b51f10903e044308cf77117c0ed9871350475","target":{"file":"tensorflow/core/kernels/pooling_ops_common.cc"}},{"deprecated":false,"digest":{"line_hashes":["321510953903970165784769487578693180000","220851792359686731738435691643445972526","212858347606659837489648021025971220867","9977049370741135102315464992886612903","111528897354432503072734285107859990630","97185756686036762472331409025436480803","313525491627767760650827937378965479927","210185103215447344364381746563181112859"],"threshold":0.9},"id":"CVE-2021-37674-ec23509d","signature_type":"Line","signature_version":"v1","source":"https://github.com/tensorflow/tensorflow/commit/136b51f10903e044308cf77117c0ed9871350475","target":{"file":"tensorflow/core/kernels/maxpooling_op.cc"}}],"vanir_signatures_modified":"2026-08-07T16:57:29Z"}}],"references":[{"type":"ADVISORY","url":"https://github.com/tensorflow/tensorflow/blob/master/tensorflow/security/advisory/tfsa-2021-068.md"},{"type":"ADVISORY","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-7ghq-fvr3-pj2x"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/136b51f10903e044308cf77117c0ed9871350475"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}