TensorFlow has Floating Point Exception in TensorListSplit with XLA
CVE-2023-25673
7.5HIGH
What is CVE-2023-25673?
A vulnerability exists in TensorFlow, an open-source machine learning platform, where a Floating Point Exception may occur in the TensorListSplit function using XLA in versions prior to 2.12.0. This flaw could lead to application crashes or unexpected behavior in computations, potentially disrupting machine learning workflows. TensorFlow versions 2.12.0 and 2.11.1 contain a fix for this vulnerability, emphasizing the importance of updating to maintain the integrity and reliability of machine learning applications.
Affected Version(s)
tensorflow < 2.11.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved