{"id":"CVE-2021-37686","aliases":["BIT-tensorflow-2021-37686","GHSA-mhhc-q96p-mfm9","PYSEC-2021-308","PYSEC-2021-599","PYSEC-2021-797"],"url":"https://o3.security/vulnerability/CVE-2021-37686","summary":"Infinite loop in TFLite","details":"### Impact\nThe strided slice implementation in TFLite has a logic bug which can allow an attacker to trigger an infinite loop. This arises from newly introduced support for [ellipsis in axis definition](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/strided_slice.cc#L103-L122):\n\n```cc\n  for (int i = 0; i < effective_dims;) {\n    if ((1 << i) & op_context->params->ellipsis_mask) {\n      // ...\n      int ellipsis_end_idx =\n          std::min(i + 1 + num_add_axis + op_context->input_dims - begin_count,\n                   effective_dims);\n      // ...\n      for (; i < ellipsis_end_idx; ++i) {\n        // ...\n      }\n      continue;\n    }\n    // ...\n    ++i;\n  }\n```\n\nAn attacker can craft a model such that `ellipsis_end_idx` is smaller than `i` (e.g., always negative). In this case, the inner loop does not increase `i` and the `continue` statement causes execution to skip over the preincrement at the end of the outer loop.\n\n### Patches\nWe have patched the issue in GitHub commit [dfa22b348b70bb89d6d6ec0ff53973bacb4f4695](https://github.com/tensorflow/tensorflow/commit/dfa22b348b70bb89d6d6ec0ff53973bacb4f4695).\n\nThe fix will be included in TensorFlow 2.6.0. This is the only affected version.\n\n### For more information\nPlease consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.\n\n### Attribution\nThis vulnerability has been reported by members of the Aivul Team from Qihoo 360.","published":"2021-08-12T22:15:08.967Z","modified":"2026-08-07T19:46:43.698572Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"tensorflow","fixedVersion":"2.6.0rc2"},{"ecosystem":"PyPI","name":"tensorflow-cpu","fixedVersion":"2.6.0rc2"},{"ecosystem":"PyPI","name":"tensorflow-gpu","fixedVersion":"2.6.0rc2"}],"fix":{"url":"https://github.com/tensorflow/tensorflow/commit/dfa22b348b70bb89d6d6ec0ff53973bacb4f4695","label":"tensorflow/tensorflow@dfa22b3"},"references":[{"type":"ADVISORY","url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-mhhc-q96p-mfm9"},{"type":"FIX","url":"https://github.com/tensorflow/tensorflow/commit/dfa22b348b70bb89d6d6ec0ff53973bacb4f4695"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-37686"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2021-599.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2021-797.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2021-308.yaml"},{"type":"PACKAGE","url":"https://github.com/tensorflow/tensorflow"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/releases/tag/v2.3.4"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/releases/tag/v2.4.3"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/releases/tag/v2.5.1"},{"type":"WEB","url":"https://github.com/tensorflow/tensorflow/releases/tag/v2.6.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T19:46:43.698572Z"}}