CVE-2023-27579: Google Tensorflow
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
TensorFlow is an end-to-end open source platform for machine learning. Constructing a tflite model with a paramater `filter_input_channel` of less than 1 gives a FPE. This issue has been patched in version 2.12. TensorFlow will also cherrypick the fix commit on TensorFlow 2.11.1.
Affected products
- Google Tensorflow: before 2.12.0 (fixed in 2.12.0)
Published 2023-03-25. Last modified 2026-06-17.