{"api_version":"1","generated_at":"2026-07-24T01:57:58+00:00","cve":"CVE-2023-25668","urls":{"html":"https://cve.report/CVE-2023-25668","api":"https://cve.report/api/cve/CVE-2023-25668.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-25668","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-25668"},"summary":{"title":"CVE-2023-25668","description":"TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2023-03-25 00:15:00","updated_at":"2023-03-31 14:20:00"},"problem_types":["CWE-125","CWE-122"],"metrics":[],"references":[{"url":"https://github.com/tensorflow/tensorflow/commit/7b174a0f2e40ff3f3aa957aecddfd5aaae35eccb","name":"https://github.com/tensorflow/tensorflow/commit/7b174a0f2e40ff3f3aa957aecddfd5aaae35eccb","refsource":"MISC","tags":[],"title":"Fix asan issue with QuantizeAndDequantizeV2/V3/V4/V4Grad shape infere… · tensorflow/tensorflow@7b174a0 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96","name":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96","refsource":"MISC","tags":[],"title":"A heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation · Advisory · tensorflow/tensorflow · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-25668","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25668","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"25668","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"tensorflow","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-25668","qid":"907368","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for tensorflow (31200-1)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-25668","ASSIGNER":"security-advisories@github.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-122: Heap-based Buffer Overflow","cweId":"CWE-122"}]},{"description":[{"lang":"eng","value":"CWE-125: Out-of-bounds Read","cweId":"CWE-125"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"tensorflow","product":{"product_data":[{"product_name":"tensorflow","version":{"version_data":[{"version_affected":"=","version_value":"< 2.11.1"}]}}]}}]}},"references":{"reference_data":[{"url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96","refsource":"MISC","name":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96"},{"url":"https://github.com/tensorflow/tensorflow/commit/7b174a0f2e40ff3f3aa957aecddfd5aaae35eccb","refsource":"MISC","name":"https://github.com/tensorflow/tensorflow/commit/7b174a0f2e40ff3f3aa957aecddfd5aaae35eccb"}]},"source":{"advisory":"GHSA-gw97-ff7c-9v96","discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-03-25 00:15:00","lastModifiedDate":"2023-03-31 14:20:00","problem_types":["CWE-125","CWE-122"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:google:tensorflow:*:*:*:*:*:*:*:*","versionEndExcluding":"2.12.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}