{"id":"CVE-2021-37686","aliases":["GHSA-mhhc-q96p-mfm9","BIT-tensorflow-2021-37686","PYSEC-2021-308","PYSEC-2021-599","PYSEC-2021-797"],"title":"Infinite loop in TFLite","summary":"Infinite loop in TFLite","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","vendor":"tensorflow","product":"tensorflow","ecosystem":"pip","affected":["tensorflow >= 2.6.0rc0, < 2.6.0rc2","tensorflow-cpu >= 2.6.0rc0, < 2.6.0rc2","tensorflow-gpu >= 2.6.0rc0, < 2.6.0rc2"],"patched":["tensorflow 2.6.0rc2","tensorflow-cpu 2.6.0rc2","tensorflow-gpu 2.6.0rc2"],"published":"2021-08-25","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-mhhc-q96p-mfm9","references":[{"url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-mhhc-q96p-mfm9"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-37686"},{"url":"https://github.com/tensorflow/tensorflow/commit/dfa22b348b70bb89d6d6ec0ff53973bacb4f4695"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2021-599.yaml"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2021-797.yaml"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2021-308.yaml"},{"url":"https://github.com/tensorflow/tensorflow"},{"url":"https://github.com/tensorflow/tensorflow/releases/tag/v2.3.4"},{"url":"https://github.com/tensorflow/tensorflow/releases/tag/v2.4.3"},{"url":"https://github.com/tensorflow/tensorflow/releases/tag/v2.5.1"},{"url":"https://github.com/tensorflow/tensorflow/releases/tag/v2.6.0"}],"tags":["osv","pip"],"epss":0.00173,"epssPercentile":0.07032,"ingestedAt":"2026-07-08T18:25:51.223Z","slug":"CVE-2021-37686","body":"## Overview\n\n### Impact\nThe strided slice implementation in TFLite has a logic bug which can allow an attacker to trigger an infinite loop. This arises from newly introduced support for [ellipsis in axis definition](https://github.com/tensorflow/tensorflow/blob/149562d49faa709ea80df1d99fc41d005b81082a/tensorflow/lite/kernels/strided_slice.cc#L103-L122):\n\n```cc\n  for (int i = 0; i < effective_dims;) {\n    if ((1 << i) & op_context->params->ellipsis_mask) {\n      // ...\n      int ellipsis_end_idx =\n          std::min(i + 1 + num_add_axis + op_context->input_dims - begin_count,\n                   effective_dims);\n      // ...\n      for (; i < ellipsis_end_idx; ++i) {\n        // ...\n      }\n      continue;\n    }\n    // ...\n    ++i;\n  }\n```\n\nAn attacker can craft a model such that `ellipsis_end_idx` is smaller than `i` (e.g., always negative). In this case, the inner loop does not increase `i` and the `continue` statement causes execution to skip over the preincrement at the end of the outer loop.\n\n### Patches\nWe have patched the issue in GitHub commit [dfa22b348b70bb89d6d6ec0ff53973bacb4f4695](https://github.com/tensorflow/tensorflow/commit/dfa22b348b70bb89d6d6ec0ff53973bacb4f4695).\n\nThe fix will be included in TensorFlow 2.6.0. This is the only affected version.\n\n### For more information\nPlease consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.\n\n### Attribution\nThis vulnerability has been reported by members of the Aivul Team from Qihoo 360.\n\n## Affected packages\n\n- `tensorflow >= 2.6.0rc0, < 2.6.0rc2`\n- `tensorflow-cpu >= 2.6.0rc0, < 2.6.0rc2`\n- `tensorflow-gpu >= 2.6.0rc0, < 2.6.0rc2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `tensorflow 2.6.0rc2`\n- `tensorflow-cpu 2.6.0rc2`\n- `tensorflow-gpu 2.6.0rc2`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}