CVE-2023-25659: TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
Published Mar 24, 2023
·Updated
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter indices for DynamicStitch does not match the shape of the parameter data, it can trigger an stack OOB read. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
Affected Software
1 affected component
Google TensorFlow<2.12.0
Remediation
Event History
Mar 24, 2023
CVE Published
via MITRE·11:43 PM
Data Sourced
via MITRE·11:43 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is TensorFlow?
TensorFlow is an open source platform for machine learning.
2
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25659.
3
What is the severity of CVE-2023-25659?
The severity of CVE-2023-25659 is high (7.5).
4
What is the fix for CVE-2023-25659?
The fix for CVE-2023-25659 is included in TensorFlow versions 2.12.0 and 2.11.1.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-25659?
The Common Weakness Enumeration (CWE) for CVE-2023-25659 is CWE-125.