Safety vulnerability ID: 53849
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Tensorflow 2.11.1 and 2.12.0 include a fix for CVE-2023-25663: Prior to versions 2.12.0 and 2.11.1, when 'ctx->step_containter()' is a null ptr, the Lookup function will be executed with a null pointer.
https://github.com/tensorflow/tensorflow/security/advisories/GHSA-64jg-wjww-7c5w
Latest version: 2.18.0
TensorFlow is an open source machine learning framework for everyone.
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_containter()` is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 and 2.11.1. See CVE-2023-25663.
MISC:https://github.com/tensorflow/tensorflow/commit/239139d2ae6a81ae9ba499ad78b56d9b2931538a: https://github.com/tensorflow/tensorflow/commit/239139d2ae6a81ae9ba499ad78b56d9b2931538a
MISC:https://github.com/tensorflow/tensorflow/security/advisories/GHSA-64jg-wjww-7c5w: https://github.com/tensorflow/tensorflow/security/advisories/GHSA-64jg-wjww-7c5w
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application