-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability CVE-2023-25658 specifically mentions an out-of-bounds read in GRUBlockCellGrad. The commit diff shows significant validation checks added to GRUBlockCellGradOp::Compute in gru_ops.cc, including rank checks for input tensors (x, h_prev, w_ru, etc.) and dimension comparisons. These checks were absent in vulnerable versions, allowing malformed inputs to trigger OOB reads. The patch adds explicit validation for tensor shapes, confirming this was the vulnerable entry point.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| tensorflow | pip | < 2.11.1 | 2.11.1 |
| tensorflow-cpu | pip | < 2.11.1 | 2.11.1 |
| tensorflow-gpu | pip | < 2.11.1 | 2.11.1 |
Ongoing coverage of React2Shell