CVE-2023-25676
25.03.2023, 00:15
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.ParallelConcat` segfaults with a nullptr dereference when given a parameter `shape` with rank that is not greater than zero. A fix is available in TensorFlow 2.12.0 and 2.11.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tensorflow | 𝑥 < 2.12.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tensorflow | tensorflow | 𝑥 < 2.11.1 | CNA |
Common Weakness Enumeration
References