CVE-2023-25671: TensorFlow has segmentation fault in tfg-translate
Published Mar 24, 2023
·Updated
TensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
Affected Software
1 affected component
Google TensorFlow<2.12.0
Remediation
Event History
Mar 24, 2023
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25671?
CVE-2023-25671 is a vulnerability in TensorFlow, an open source platform for machine learning, that allows for out-of-bounds access due to mismatched integer type sizes.
2
What is the severity of CVE-2023-25671?
CVE-2023-25671 has a severity rating of high, with a severity value of 7.5.
3
What is the affected software for CVE-2023-25671?
The affected software for CVE-2023-25671 is TensorFlow version up to exclusive 2.12.0.
4
How can I fix CVE-2023-25671?
To fix CVE-2023-25671, it is recommended to update TensorFlow to version 2.12.0 or version 2.11.1.
5
Is there any additional information about CVE-2023-25671?
Yes, you can find additional information about CVE-2023-25671 in the references provided.