TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
CVE-2023-25659

7.5HIGH

Key Information:

Vendor

Tensorflow

Vendor
CVE Published:
25 March 2023

What is CVE-2023-25659?

In TensorFlow, an open-source machine learning platform, a vulnerability exists in the functionality of 'DynamicStitch' where the parameter 'indices' may not align correctly with the 'data' parameter shape. This misalignment can lead to an out-of-bounds read, potentially allowing the reading of unintended memory areas. The issue has been addressed in TensorFlow versions 2.12.0 and 2.11.1, which include fixes to prevent such occurrences.

Affected Version(s)

tensorflow < 2.11.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.