First published: Fri Mar 24 2023(Updated: )
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a heap buffer overflow in TAvgPoolGrad. A fix is included in TensorFlow 2.12.0 and 2.11.1.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google TensorFlow | <2.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25664 is a heap buffer overflow vulnerability in TAvgPoolGrad in TensorFlow versions prior to 2.12.0 and 2.11.1.
The severity of CVE-2023-25664 is critical, with a CVSS score of 9.8.
CVE-2023-25664 affects TensorFlow versions prior to 2.12.0 and 2.11.1.
Yes, a fix is included in TensorFlow 2.12.0 and 2.11.1.
You can find more information about CVE-2023-25664 on the GitHub commit and security advisories pages: [GitHub Commit](https://github.com/tensorflow/tensorflow/commit/ddaac2bdd099bec5d7923dea45276a7558217e5b), [Security Advisories](https://github.com/tensorflow/tensorflow/security/advisories/GHSA-6hg6-5c2q-7rcr).