TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
CVE-2023-25659
7.5HIGH
What is CVE-2023-25659?
In TensorFlow, an open-source machine learning platform, a vulnerability exists in the functionality of 'DynamicStitch' where the parameter 'indices' may not align correctly with the 'data' parameter shape. This misalignment can lead to an out-of-bounds read, potentially allowing the reading of unintended memory areas. The issue has been addressed in TensorFlow versions 2.12.0 and 2.11.1, which include fixes to prevent such occurrences.
Affected Version(s)
tensorflow < 2.11.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved