Safety vulnerability ID: 56483
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Tflite-runtime 2.8.0 includes a fix for CVE-2022-23559: An attacker can craft a TFLite model that would cause an integer overflow in embedding lookup operations. Both 'embedding_size' and 'lookup_size' are products of values provided by the user. Hence, a malicious user could trigger overflows in the multiplication. In certain scenarios, this can then result in heap OOB read/write.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-98p5-x8x4-c9m5
Latest version: 2.14.0
TensorFlow Lite is for mobile and embedded devices.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application