PT-2023-20225 · Google · Tensorflow
Published
2023-03-24
·
Updated
2024-03-06
·
CVE-2023-25664
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
TensorFlow versions prior to 2.12.0 and 2.11.1
Description
There is a heap buffer overflow in TAvgPoolGrad. The issue can be exploited by using the
tf.raw ops.AvgPoolGrad function with specific parameters, such as ksize, strides, padding, data format, orig input shape, and grad. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.Recommendations
For versions prior to 2.12.0, update to TensorFlow 2.12.0 to resolve the issue.
For versions prior to 2.11.1, update to TensorFlow 2.11.1 to resolve the issue.
As a temporary workaround, consider avoiding the use of the
tf.raw ops.AvgPoolGrad function until a patch is applied.Exploit
Fix
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tensorflow