PT-2023-20232 · Google · Tensorflow

R3Pwnx

·

Published

2023-03-24

·

Updated

2024-03-06

·

CVE-2023-25670

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.12.0 TensorFlow versions prior to 2.11.1
Description TensorFlow is an open source platform for machine learning. The issue is a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
Recommendations For versions prior to 2.12.0, update to version 2.12.0 to resolve the issue. For versions prior to 2.11.1, update to version 2.11.1 to resolve the issue. As a temporary workaround, consider disabling the QuantizedMatMulWithBiasAndDequantize function with MKL enabled until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-31214
AZL-35315
BIT-TENSORFLOW-2023-25670
CVE-2023-25670
GHSA-49RQ-HWC3-X77W

Affected Products

Tensorflow