-
CVSS Score
-The vulnerability stems directly from the LookupTableImportV2 implementation in lookup_ops.cc. The commit diff shows the fix changed the rank check from WithRank() to WithRankAtLeast(1) for the values input, and the test case explicitly demonstrates scalar values trigger the issue. The CWE-476 classification confirms this is a NULL pointer dereference scenario caused by improper input validation in this specific function.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| tensorflow | pip | < 2.11.1 | 2.11.1 |
| tensorflow-cpu | pip | < 2.11.1 | 2.11.1 |
| tensorflow-gpu | pip | < 2.11.1 | 2.11.1 |
Ongoing coverage of React2Shell