CVE-2023-25669: TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the stride and window size are not positive for tf.rawops.AvgPoolGrad, it can give a floating point exception. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25669.
What is the severity of CVE-2023-25669?
The severity of CVE-2023-25669 is high, with a severity value of 7.5.
How does CVE-2023-25669 affect TensorFlow?
CVE-2023-25669 affects TensorFlow versions prior to 2.12.0 and 2.11.1.
What is the fix for CVE-2023-25669?
The fix for CVE-2023-25669 is included in TensorFlow version 2.12.0 and version 2.11.1.
Where can I find more information about CVE-2023-25669?
You can find more information about CVE-2023-25669 in the following references: [GitHub Commit](https://github.com/tensorflow/tensorflow/commit/1295ae4dbb52fe06b19733b0257e2340d7b63b8d), [Security Advisory](https://github.com/tensorflow/tensorflow/security/advisories/GHSA-rcf8-g8jv-vg6p).