Aller au contenu

Fiche vulnérabilité

CVE-2023-25675 : faille élevée google tensorflow (CVSS 7.5)

Description

TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.Bincount` segfaults when given a parameter `weights` that is neither the same shape as parameter `arr` nor a length-0 tensor. A fix is included in TensorFlow 2.12.0 and 2.11.1.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
25 mars 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • google tensorflow

Références

Rechercher une autre vulnérabilité dans la base CVE