Back to Database
Status published
High
CVE-2023-33976
TensorFlow segfault in array_ops.upper_bound
Vulnerability Description
TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be included in TensorFlow 2.13 and will also cherrypick this commit on TensorFlow 2.12.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-33976
Credits & Attribution
No credits recorded in the NVD database.
References
More from tensorflow
View All →CVE-2024-3660
Arbitrary code injection vulnerability in Keras framework < 2.13
Unknown
0
CVE-2023-27579
TensorFlow has Floating Point Exception in TFLite in conv kernel
High
7.5
CVE-2023-25801
TensorFlow has double free in Fractional(Max/Avg)Pool
High
8
CVE-2023-25676
TensorFlow has null dereference on ParallelConcat with XLA
High
7.5
CVE-2023-25675
TensorFlow has Segfault in Bincount with XLA
High
7.5
Affected Vendor
tensorflow
View all reports →Affected Software
tensorflow
Vulnerable Versions:
< 2.13.0
Timeline
Official Publish:
July 30th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H