{"id":"CVE-2023-25662","aliases":["GHSA-7jvm-xxmr-v5cw","BIT-tensorflow-2023-25662","PYSEC-2026-1958","PYSEC-2026-3130","PYSEC-2026-3293"],"title":"TensorFlow vulnerable to integer overflow in EditDistance","summary":"TensorFlow vulnerable to integer overflow in EditDistance","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"tensorflow","product":"tensorflow","ecosystem":"pip","affected":["tensorflow < 2.11.1","tensorflow-cpu < 2.11.1","tensorflow-gpu < 2.11.1"],"patched":["tensorflow 2.11.1","tensorflow-cpu 2.11.1","tensorflow-gpu 2.11.1"],"published":"2023-03-24","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:52.814678965Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7jvm-xxmr-v5cw","references":[{"url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-7jvm-xxmr-v5cw"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25662"},{"url":"https://github.com/tensorflow/tensorflow/commit/08b8e18643d6dcde00890733b270ff8d9960c56c"},{"url":"https://github.com/tensorflow/tensorflow"}],"tags":["osv","pip"],"epss":0.00394,"epssPercentile":0.33429,"ingestedAt":"2026-07-08T18:25:47.042Z","slug":"CVE-2023-25662","body":"## Overview\n\n### Impact\nTFversion 2.11.0 //tensorflow/core/ops/array_ops.cc:1067 const Tensor* hypothesis_shape_t = c->input_tensor(2); std::vector<DimensionHandle> dims(hypothesis_shape_t->NumElements() - 1); for (int i = 0; i < dims.size(); ++i) { dims[i] = c->MakeDim(std::max(h_values(i), t_values(i))); }\n\nif hypothesis_shape_t is empty, hypothesis_shape_t->NumElements() - 1 will be integer overflow, and the it will deadlock\n```python\nimport tensorflow as tf\npara={\n    'hypothesis_indices': [[]],\n    'hypothesis_values': ['tmp/'],\n    'hypothesis_shape': [],\n    'truth_indices': [[]],\n    'truth_values': [''],\n    'truth_shape': [],\n    'normalize': False\n    }\ntf.raw_ops.EditDistance(**para)\n```\n\n### Patches\nWe have patched the issue in GitHub commit [08b8e18643d6dcde00890733b270ff8d9960c56c](https://github.com/tensorflow/tensorflow/commit/08b8e18643d6dcde00890733b270ff8d9960c56c).\n\nThe fix will be included in TensorFlow 2.12.0. We will also cherrypick this commit on TensorFlow 2.11.1\n\n\n### For more information\nPlease consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.\n\n\n### Attribution\nThis vulnerability has been reported by r3pwnx\n\n## Affected packages\n\n- `tensorflow < 2.11.1`\n- `tensorflow-cpu < 2.11.1`\n- `tensorflow-gpu < 2.11.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `tensorflow 2.11.1`\n- `tensorflow-cpu 2.11.1`\n- `tensorflow-gpu 2.11.1`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}