PT-2023-21221 · Google · Tensorflow

Wang Xuan

·

Published

2023-03-24

·

Updated

2024-03-06

·

CVE-2023-27579

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TensorFlow versions prior to 2.12 TensorFlow version 2.11.1 and earlier
Description Constructing a tflite model with a parameter filter input channel of less than 1 gives a Floating Point Exception (FPE). This issue affects TensorFlow, an end-to-end open source platform for machine learning.
Recommendations For versions prior to 2.12, update to version 2.12 or later to resolve the issue. For version 2.11.1 and earlier, wait for the fix commit to be cherry-picked or update to a newer version when available. As a temporary workaround, consider avoiding the construction of tflite models with a filter input channel parameter of less than 1 until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

AZL-31208
AZL-35323
BIT-TENSORFLOW-2023-27579
CVE-2023-27579
GHSA-5W96-866F-6RM8

Affected Products

Tensorflow