CVE-2023-25676: TensorFlow has null dereference on ParallelConcat with XLA
Published Mar 24, 2023
·Updated
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, tf.rawops.ParallelConcat segfaults with a nullptr dereference when given a parameter shape with rank that is not greater than zero. A fix is available in TensorFlow 2.12.0 and 2.11.1.
Affected Software
1 affected component
Google TensorFlow<2.12.0
Remediation
Event History
Mar 24, 2023
CVE Published
via MITRE·11:10 PM
Data Sourced
via MITRE·11:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this TensorFlow vulnerability?
The vulnerability ID of this TensorFlow vulnerability is CVE-2023-25676.
2
What is TensorFlow?
TensorFlow is an open source machine learning platform.
3
What is affected by this vulnerability?
Versions of TensorFlow prior to 2.12.0 and 2.11.1 with XLA are affected by this vulnerability.
4
What is the severity of this vulnerability?
The severity of this vulnerability is high with a CVSS score of 7.5.
5
How can I fix this TensorFlow vulnerability?
To fix this TensorFlow vulnerability, update to version 2.12.0 or 2.11.1.