PT-2025-39417 · Google · Tensorflow

Published

2025-01-06

·

Updated

2025-10-05

·

CVE-2025-55559

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions TensorFlow version 2.18.0
Description A Denial of Service (DoS) issue exists in TensorFlow. Specifically, the problem occurs within the tf.keras.layers.Conv2D layer when the padding parameter is set to 'valid'. This configuration can lead to a denial of service condition.
Recommendations Avoid setting the padding parameter to 'valid' in tf.keras.layers.Conv2D to mitigate the risk.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2025-12839
BIT-TENSORFLOW-2025-55559
CVE-2025-55559

Affected Products

Tensorflow