CVE-2023-25664: TensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-25664?
CVE-2023-25664 is a heap buffer overflow vulnerability in TAvgPoolGrad in TensorFlow versions prior to 2.12.0 and 2.11.1.
What is the severity of CVE-2023-25664?
The severity of CVE-2023-25664 is critical, with a CVSS score of 9.8.
How does CVE-2023-25664 affect the software?
CVE-2023-25664 affects TensorFlow versions prior to 2.12.0 and 2.11.1.
Is there a fix available for CVE-2023-25664?
Yes, a fix is included in TensorFlow 2.12.0 and 2.11.1.
Where can I find more information about CVE-2023-25664?
You can find more information about CVE-2023-25664 on the GitHub commit and security advisories pages: [GitHub Commit](https://github.com/tensorflow/tensorflow/commit/ddaac2bdd099bec5d7923dea45276a7558217e5b), [Security Advisories](https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6hg6-5c2q-7rcr).