---
id: CVE-2023-25662
aliases:
  - GHSA-7jvm-xxmr-v5cw
  - BIT-tensorflow-2023-25662
  - PYSEC-2026-1958
  - PYSEC-2026-3130
  - PYSEC-2026-3293
title: TensorFlow vulnerable to integer overflow in EditDistance
summary: TensorFlow vulnerable to integer overflow in EditDistance
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: tensorflow
product: tensorflow
ecosystem: pip
affected:
  - tensorflow < 2.11.1
  - tensorflow-cpu < 2.11.1
  - tensorflow-gpu < 2.11.1
patched:
  - tensorflow 2.11.1
  - tensorflow-cpu 2.11.1
  - tensorflow-gpu 2.11.1
published: '2023-03-24'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:52.814678965Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7jvm-xxmr-v5cw'
references:
  - url: >-
      https://github.com/tensorflow/tensorflow/security/advisories/GHSA-7jvm-xxmr-v5cw
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-25662'
  - url: >-
      https://github.com/tensorflow/tensorflow/commit/08b8e18643d6dcde00890733b270ff8d9960c56c
  - url: 'https://github.com/tensorflow/tensorflow'
tags:
  - osv
  - pip
epss: 0.00394
epssPercentile: 0.30864
ingestedAt: '2026-07-08T18:25:47.042Z'
---

## Overview

### Impact
TFversion 2.11.0 //tensorflow/core/ops/array_ops.cc:1067 const Tensor* hypothesis_shape_t = c->input_tensor(2); std::vector<DimensionHandle> dims(hypothesis_shape_t->NumElements() - 1); for (int i = 0; i < dims.size(); ++i) { dims[i] = c->MakeDim(std::max(h_values(i), t_values(i))); }

if hypothesis_shape_t is empty, hypothesis_shape_t->NumElements() - 1 will be integer overflow, and the it will deadlock
```python
import tensorflow as tf
para={
    'hypothesis_indices': [[]],
    'hypothesis_values': ['tmp/'],
    'hypothesis_shape': [],
    'truth_indices': [[]],
    'truth_values': [''],
    'truth_shape': [],
    'normalize': False
    }
tf.raw_ops.EditDistance(**para)
```

### Patches
We have patched the issue in GitHub commit [08b8e18643d6dcde00890733b270ff8d9960c56c](https://github.com/tensorflow/tensorflow/commit/08b8e18643d6dcde00890733b270ff8d9960c56c).

The fix will be included in TensorFlow 2.12.0. We will also cherrypick this commit on TensorFlow 2.11.1


### For more information
Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.


### Attribution
This vulnerability has been reported by r3pwnx

## Affected packages

- `tensorflow < 2.11.1`
- `tensorflow-cpu < 2.11.1`
- `tensorflow-gpu < 2.11.1`

## Remediation

Upgrade to a patched release:

- `tensorflow 2.11.1`
- `tensorflow-cpu 2.11.1`
- `tensorflow-gpu 2.11.1`
