TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
CVE-2023-25659
7.5HIGH
What is CVE-2023-25659?
In TensorFlow, an open-source machine learning platform, a vulnerability exists in the functionality of 'DynamicStitch' where the parameter 'indices' may not align correctly with the 'data' parameter shape. This misalignment can lead to an out-of-bounds read, potentially allowing the reading of unintended memory areas. The issue has been addressed in TensorFlow versions 2.12.0 and 2.11.1, which include fixes to prevent such occurrences.
Affected Version(s)
tensorflow < 2.11.1