CVE-2023-25674

Severity
7.5HIGH
EPSS
0.4%
top 39.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
Latest updateMar 24
PublishedMar 25

Description

TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled. A fix is included in TensorFlow 2.12.0 and 2.11.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

PyPItensorflow< 2.11.1
PyPItensorflow-cpu< 2.11.1
PyPItensorflow-gpu< 2.11.1
NVDgoogle/tensorflow< 2.12.0
CVEListV5tensorflow/tensorflow< 2.11.1

Patches

🔴Vulnerability Details

3
CVEList
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable2023-03-24
OSV
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable2023-03-24
GHSA
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable2023-03-24

📋Vendor Advisories

2
Microsoft
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable2023-03-14
Debian
CVE-2023-25674: tensorflow - TensorFlow is an open source machine learning platform. Versions prior to 2.12.0...2023
CVE-2023-25674 (HIGH CVSS 7.5) | TensorFlow is an open source machin | cvebase.io