CVE-2023-25662: TensorFlow vulnerable to integer overflow in EditDistance
Published Mar 24, 2023
·Updated
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
Affected Software
1 affected component
Google TensorFlow<2.12.0
Remediation
Event History
Mar 24, 2023
CVE Published
via MITRE·11:41 PM
Data Sourced
via MITRE·11:41 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this TensorFlow vulnerability?
The vulnerability ID is CVE-2023-25662.
2
What is TensorFlow?
TensorFlow is an open source platform for machine learning.
3
What is the severity of CVE-2023-25662?
The severity of CVE-2023-25662 is high.
4
Which versions of TensorFlow are affected by CVE-2023-25662?
Versions prior to 2.12.0 and 2.11.1 are affected by CVE-2023-25662.
5
How do I fix CVE-2023-25662 in TensorFlow?
You can fix CVE-2023-25662 by updating TensorFlow to version 2.12.0 or version 2.11.1.