TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when ctx->step_containter()
is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 and 2.11.1.
{ "vanir_signatures": [ { "id": "CVE-2023-25663-10f53fcf", "signature_type": "Function", "digest": { "function_hash": "35885794639007058225458304983826073081", "length": 477.0 }, "target": { "file": "tensorflow/core/kernels/tensor_array_ops.cc", "function": "GetTensorArray" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/tensorflow/tensorflow/commit/239139d2ae6a81ae9ba499ad78b56d9b2931538a" }, { "id": "CVE-2023-25663-2260bdd8", "signature_type": "Line", "digest": { "line_hashes": [ "264465115802930545512537044350893918741", "299685002815380107120215548555878734185", "133088477667571187684744172061314777758", "159936062196770601467024760985439427358", "119401361397129384390260475616212947017" ], "threshold": 0.9 }, "target": { "file": "tensorflow/core/kernels/tensor_array_ops.cc" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/tensorflow/tensorflow/commit/239139d2ae6a81ae9ba499ad78b56d9b2931538a" } ] }