CVE-2018-21233: Google Tensorflow

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.

Affected products

  • Google Tensorflow: before 1.7.0 (fixed in 1.7.0)

Published 2020-05-04. Last modified 2026-06-17.