GHSA-5w96-866f-6rm8

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-5w96-866f-6rm8/GHSA-5w96-866f-6rm8.json
Aliases
  • CVE-2023-27579
Published
2023-03-24T21:53:39Z
Modified
2023-04-11T01:27:11.465699Z
Details

Impact

Constructing a tflite model with a paramater filter_input_channel of less than 1 gives a FPE.

Patches

We have patched the issue in GitHub commit 34f8368c535253f5c9cb3a303297743b62442aaa.

The fix will be included in TensorFlow 2.12. We will also cherrypick this commit on TensorFlow 2.11.1.

For more information

Please consult our security guide for more information regarding the security model and how to contact us with issues and questions.

Attribution

This vulnerability was reported by Wang Xuan of Qihoo 360 AIVul Team.

References

Affected packages

PyPI / tensorflow

tensorflow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
2.11.1

Affected versions

0.*

0.12.0
0.12.1

1.*

1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.12.2
1.12.3
1.13.1
1.13.2
1.14.0
1.15.0
1.15.2
1.15.3
1.15.4
1.15.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.0rc0
2.10.0rc1
2.10.0rc2
2.10.0rc3
2.10.1
2.11.0
2.11.0rc0
2.11.0rc1
2.11.0rc2
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.0rc0
2.6.0rc1
2.6.0rc2
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.0rc0
2.7.0rc1
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.0rc0
2.8.0rc1
2.8.1
2.8.2
2.8.3
2.8.4
2.9.0
2.9.0rc0
2.9.0rc1
2.9.0rc2
2.9.1
2.9.2
2.9.3

PyPI / tensorflow-cpu

tensorflow-cpu

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
2.11.1

Affected versions

1.*

1.15.0

2.*

2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.0rc0
2.10.0rc1
2.10.0rc2
2.10.0rc3
2.10.1
2.11.0
2.11.0rc0
2.11.0rc1
2.11.0rc2
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.9.0
2.9.0rc0
2.9.0rc1
2.9.0rc2
2.9.1
2.9.2
2.9.3

PyPI / tensorflow-gpu

tensorflow-gpu

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
2.11.1

Affected versions

0.*

0.12.0
0.12.1

1.*

1.0.0
1.0.1
1.1.0
1.10.0
1.10.1
1.11.0
1.12.0
1.12.2
1.12.3
1.13.1
1.13.2
1.14.0
1.15.0
1.15.2
1.15.3
1.15.4
1.15.5
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.0rc0
2.10.0rc1
2.10.0rc2
2.10.0rc3
2.10.1
2.11.0
2.11.0rc0
2.11.0rc1
2.11.0rc2
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.7.0
2.7.0rc0
2.7.0rc1
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.0rc0
2.8.0rc1
2.8.1
2.8.2
2.8.3
2.8.4
2.9.0
2.9.0rc0
2.9.0rc1
2.9.0rc2
2.9.1
2.9.2
2.9.3