TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
CVE-2023-25674
7.5HIGH
What is CVE-2023-25674?
A null pointer error has been identified in the TensorFlow machine learning platform when the XLA (Accelerated Linear Algebra) feature is enabled. This issue affects TensorFlow versions prior to 2.12.0 and 2.11.1, potentially leading to unexpected behavior and application crashes. Users are strongly advised to upgrade to the latest versions to mitigate this vulnerability and enhance the security of their machine learning applications. A fix has been provided in TensorFlow releases 2.12.0 and 2.11.1.
Affected Version(s)
tensorflow < 2.11.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved