Google · Tensorflow · CVE-2023-25671
**Name of the Vulnerable Software and Affected Versions**
TensorFlow versions prior to 2.11.1
TensorFlow versions prior to 2.12.0
**Description**
TensorFlow is an open source platform for machine learning. There is out-of-bounds access due to mismatched integer type sizes. The issue is related to the `ValueMap::Manager::GetValueOrCreatePlaceholder` function and affects generic functions, which are using the "old importer".
**Recommendations**
For versions prior to 2.11.1, update to version 2.11.1 to resolve the issue.
For versions prior to 2.12.0, update to version 2.12.0 to resolve the issue.