Vulnerability Description
TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tensorflow | < 2.12.0 |
Related Weaknesses (CWE)
References
- https://github.com/tensorflow/tensorflow/commit/7b174a0f2e40ff3f3aa957aecddfd5aaExploitPatch
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96Patch
- https://github.com/tensorflow/tensorflow/commit/7b174a0f2e40ff3f3aa957aecddfd5aaExploitPatch
- https://github.com/tensorflow/tensorflow/security/advisories/GHSA-gw97-ff7c-9v96Patch
FAQ
What is CVE-2023-25668?
CVE-2023-25668 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remot...
How severe is CVE-2023-25668?
CVE-2023-25668 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-25668?
Check the references section above for vendor advisories and patch information. Affected products include: Google Tensorflow.