Skip to content
TensorFlowGHSA-gjh7-xx4r-x345

TensorFlow has segfault in array_ops.upper_bound

High7.5CVE-2023-33976 · Published Jul 30, 2024 · updated Jul 13, 2026

### Impact `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. ### Patches We have patched the issue in GitHub commit [915884fdf5df34aaedd00fc6ace33a2cfdefa586](https://github.com/tensorflow/tensorflow/commit/915884fdf5df34aaedd00fc6ace33a2cfdefa586). The fix will be included in TensorFlow 2.13. We will also cherrypick this commit in TensorFlow 2.12.1. ### For more information Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions. ### Attribution This vulnerability has been reported by dmc1778

GitHub advisory

Affected versions

PackageAffectedFixed in
tensorflow
PyPI
< 2.12.12.12.1
Details and references

More TensorFlow advisories

All TensorFlow
Advisory
TensorFlow Denial of Service vulnerability
Medium6.5Mar 27, 2023
TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
High7.5Mar 24, 2023
TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`
High7.5Mar 24, 2023
TensorFlow vulnerable to integer overflow in EditDistance
High7.5Mar 24, 2023
TensorFlow has Null Pointer Error in TensorArrayConcatV2
High7.5Mar 24, 2023
TensorFlow has Heap-buffer-overflow in AvgPoolGrad
High7.5Mar 24, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.