TensorFlow has segmentation fault in tfg-translate
High7.5CVE-2023-25671 · Published Mar 24, 2023 · updated Jul 13, 2026
### Impact Out-of-bounds access due to mismatched integer type sizes in ValueMap::Manager::GetValueOrCreatePlaceholder. Bug with tfg-translate call to InitMlir. The problem happens with generic functions, as it is already handled for non-generic functions. This is because they, unlike non-generic functions, are using the "old importer". A better long-term solution may be to have the "new importer" handle generic functions. ### Patches We have patched the issue in GitHub - commit [760322a71ac9033e122ef1f4b1c62813021e5938](https://github.com/tensorflow/tensorflow/commit/760322a71ac9033e122ef1f4b1c62813021e5938). - commit [2eedc8f676d2c3b8be9492e547b2bc814c10b367](https://github.com/tensorflow/tensorflow/commit/2eedc8f676d2c3b8be9492e547b2bc814c10b367) The fix will be included in TensorFlow 2.12.0. We will also cherrypick this commit on TensorFlow 2.11.1 ### For more information Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions. ### Attribution This vulnerability has been reported by r3pwnx ### Affiliation 360 AIVul
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| tensorflow PyPI | < 2.11.1 | 2.11.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-787
- Also known as
- BIT-tensorflow-2023-25671, CVE-2023-25671, PYSEC-2026-1953, PYSEC-2026-3206
- github.com/tensorflow/tensorflow/security/advisories/GHSA-j5w9-hmfh-4cr6
- nvd.nist.gov/vuln/detail/CVE-2023-25671
- github.com/tensorflow/tensorflow/commit/2eedc8f676d2c3b8be9492e547b2bc814c10b367
- github.com/tensorflow/tensorflow/commit/760322a71ac9033e122ef1f4b1c62813021e5938
- github.com/tensorflow/tensorflow
More TensorFlow advisories
All TensorFlow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 242023 | TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch | High7.5 | 2.11.1 |
| Mar 242023 | TensorFlow vulnerable to seg fault in `tf.raw_ops.Print` | High7.5 | 2.11.1 |
| Mar 242023 | TensorFlow vulnerable to integer overflow in EditDistance | High7.5 | 2.11.1 |
| Mar 242023 | TensorFlow has Null Pointer Error in TensorArrayConcatV2 | High7.5 | 2.11.1 |
| Mar 242023 | TensorFlow has Heap-buffer-overflow in AvgPoolGrad | High7.5 | 2.11.1 |
| Mar 242023 | TensorFlow has Null Pointer Error in SparseSparseMaximum | High7.5 | 2.11.1 |