PT-2023-20225 · Google · Tensorflow
Publicado
2023-03-24
·
Atualizado
2024-03-06
·
CVE-2023-25664
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
TensorFlow versions prior to 2.12.0 and 2.11.1
Description
There is a heap buffer overflow in TAvgPoolGrad. The issue can be exploited by using the
tf.raw ops.AvgPoolGrad function with specific parameters, such as ksize, strides, padding, data format, orig input shape, and grad. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.Recommendations
For versions prior to 2.12.0, update to TensorFlow 2.12.0 to resolve the issue.
For versions prior to 2.11.1, update to TensorFlow 2.11.1 to resolve the issue.
As a temporary workaround, consider avoiding the use of the
tf.raw ops.AvgPoolGrad function until a patch is applied.Exploit
Correção
Heap Based Buffer Overflow
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tensorflow