{"id":"CVE-2023-25671","aliases":["GHSA-j5w9-hmfh-4cr6","BIT-tensorflow-2023-25671","PYSEC-2026-1953"],"title":"TensorFlow has segmentation fault in tfg-translate ","summary":"TensorFlow has segmentation fault in tfg-translate ","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"tensorflow","product":"tensorflow","ecosystem":"pip","affected":["tensorflow < 2.11.1","tensorflow-cpu < 2.11.1"],"patched":["tensorflow 2.11.1","tensorflow-cpu 2.11.1"],"published":"2023-03-24","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-j5w9-hmfh-4cr6","references":[{"url":"https://github.com/tensorflow/tensorflow/security/advisories/GHSA-j5w9-hmfh-4cr6"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25671"},{"url":"https://github.com/tensorflow/tensorflow/commit/2eedc8f676d2c3b8be9492e547b2bc814c10b367"},{"url":"https://github.com/tensorflow/tensorflow/commit/760322a71ac9033e122ef1f4b1c62813021e5938"},{"url":"https://github.com/tensorflow/tensorflow"}],"tags":["osv","pip"],"epss":0.0052,"epssPercentile":0.43021,"ingestedAt":"2026-07-08T18:25:50.593Z","slug":"CVE-2023-25671","body":"## Overview\n\n### Impact\nOut-of-bounds access due to mismatched integer type sizes in ValueMap::Manager::GetValueOrCreatePlaceholder. Bug with tfg-translate call to InitMlir. The problem happens with generic functions, as it is already handled for non-generic functions. This is because they, unlike non-generic functions, are using the \"old importer\". A better long-term solution may be to have the \"new importer\" handle generic functions.\n\n### Patches\nWe have patched the issue in GitHub\n- commit [760322a71ac9033e122ef1f4b1c62813021e5938](https://github.com/tensorflow/tensorflow/commit/760322a71ac9033e122ef1f4b1c62813021e5938).\n- commit [2eedc8f676d2c3b8be9492e547b2bc814c10b367](https://github.com/tensorflow/tensorflow/commit/2eedc8f676d2c3b8be9492e547b2bc814c10b367)\n\nThe fix will be included in TensorFlow 2.12.0. We will also cherrypick this commit on TensorFlow 2.11.1\n\n\n### For more information\nPlease consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.\n\n\n### Attribution\nThis vulnerability has been reported by r3pwnx\n\n### Affiliation\n360 AIVul\n\n\n\n## Affected packages\n\n- `tensorflow < 2.11.1`\n- `tensorflow-cpu < 2.11.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `tensorflow 2.11.1`\n- `tensorflow-cpu 2.11.1`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}