CVE-2023-25668
Summary
| CVE | CVE-2023-25668 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-25 00:15:00 UTC |
| Updated | 2023-03-31 14:20:00 UTC |
| Description | TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1. |
Risk And Classification
Problem Types: CWE-125 | CWE-122
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tensorflow | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix asan issue with QuantizeAndDequantizeV2/V3/V4/V4Grad shape infere… · tensorflow/tensorflow@7b174a0 · GitHub | MISC | github.com | |
| A heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation · Advisory · tensorflow/tensorflow · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 907368 Common Base Linux Mariner (CBL-Mariner) Security Update for tensorflow (31200-1)