cbcvebase.
CVE-2023-25668
published 2023-03-25

CVE-2023-25668: TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiantensorflow
googletensorflow< 2.12.02.12.0
inteloptimization_for_tensorflow>= 0 < 2.11.12.11.1
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_tensorflow_2.11.1-1_on_cbl_mariner_2.0
tensorflowtensorflow< 2.11.12.11.1