cbcvebase.
CVE-2023-25668
published 2023-03-25

CVE-2023-25668: TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the…

PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.83%
53.5th percentile
TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiantensorflow
googletensorflow< 2.12.02.12.0
inteloptimization_for_tensorflow>= 0 < 2.11.12.11.1
msrcazl3_tensorflow_2.11.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_tensorflow_2.11.1-1_on_cbl_mariner_2.0
tensorflowtensorflow< 2.11.12.11.1

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability exists in TensorFlow's QuantizeAndDequantize operation — monitor for exploitation attempts targeting this specific op via heap out-of-buffer read
  • Affected versions are TensorFlow prior to 2.12.0 or 2.11.1; flag any environment running older versions as at-risk for crash or RCE
  • ·Scope is listed as local, limiting remote exploitation surface in default configurations
  • ·Fix is available in TensorFlow 2.12.0 and backported to 2.11.1; environments not yet patched remain exposed

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_debian9.8LOW
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.