PT-2023-20228 · Google · Tensorflow

CVE-2023-25667

·

Publicado

2023-03-24

·

Atualizado

2026-07-13

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.12.0 and 2.11.1
Description Integer overflow occurs when 2^31 <= num frames * height * width * channels < 2^32, for example, a Full HD screencast of at least 346 frames. This issue is related to the tf.io.decode gif function.
Recommendations For versions prior to 2.12.0, update to version 2.12.0 to resolve the issue. For versions prior to 2.11.1, update to version 2.11.1 to resolve the issue. As a temporary workaround, consider avoiding the use of the tf.io.decode gif function with large inputs until a patch is applied.

Exploit

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-31198
AZL-35312
BIT-TENSORFLOW-2023-25667
CVE-2023-25667
GHSA-FQM2-GH8W-GR68
PYSEC-2026-1961
PYSEC-2026-3176
PYSEC-2026-3321

Produtos afetados

Tensorflow