CVE-2023-25668

CRITICAL

TensorFlow < 2.12.0 - Out-of-bounds Read

Title source: llm
STIX 2.1

Description

TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and will also cherrypick this commit on TensorFlow version 2.11.1.

Scores

CVSS v3 9.8
EPSS 0.0083
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-122 CWE-125
Status published
Products (4)
google/tensorflow < 2.12.0
pypi/tensorflow 0 - 2.11.1PyPI
pypi/tensorflow-cpu 0 - 2.11.1PyPI
pypi/tensorflow-gpu 0 - 2.11.1PyPI
Published Mar 25, 2023
Tracked Since Feb 18, 2026