CVE-2023-25663: TensorFlow has Null Pointer Error in TensorArrayConcatV2
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when ctx->stepcontainter() is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 and 2.11.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-25663?
CVE-2023-25663 is a vulnerability in TensorFlow.
What is the severity of CVE-2023-25663?
The severity of CVE-2023-25663 is high with a score of 7.5.
How does CVE-2023-25663 affect TensorFlow?
CVE-2023-25663 affects TensorFlow versions prior to 2.12.0 and 2.11.1.
How can I fix CVE-2023-25663?
To fix CVE-2023-25663, update TensorFlow to versions 2.12.0 or 2.11.1.
Where can I find more information about CVE-2023-25663?
More information about CVE-2023-25663 can be found in the following references: [reference 1](https://github.com/tensorflow/tensorflow/commit/239139d2ae6a81ae9ba499ad78b56d9b2931538a) and [reference 2](https://github.com/tensorflow/tensorflow/security/advisories/GHSA-64jg-wjww-7c5w).