<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:14:21.326900+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-25659</id>
    <title>CVE-2023-25659 — TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch</title>
    <updated>2026-10-03T22:14:21.328531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> tensorflow</p>
<p>TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indices` for `DynamicStitch` does not match the shape of the parameter `data`, it can trigger an stack OOB read. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-25659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-93vr-9q9m-pj8p</id>
    <title>GHSA-93vr-9q9m-pj8p — TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch</title>
    <updated>2026-10-03T22:14:21.328585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu</p>
<p>### Impact
If the parameter `indices` for `DynamicStitch` does not match the shape of the parameter `data`, it can trigger an stack OOB read.</p>
<p>```python
import tensorflow as tf
func = tf.raw_ops.DynamicStitch
para={'indices': [[0xdeadbeef], [405], [519], [758], [1015]], 'data': [[110.27793884277344], [120.29475402832031], [157.2418212890625], [157.2626953125], [188.45382690429688]]}
y = func(**para)
```</p>
<p>### Patches
We have patched the issue in GitHub commit [ee004b18b976eeb5a758020af8880236cd707d05](https://github.com/tensorflow/tensorflow/commit/ee004b18b976eeb5a758020af8880236cd707d05).</p>
<p>The fix will be included in TensorFlow 2.12. We will also cherrypick this commit on TensorFlow 2.11.1.</p>
<p>### For more information
Please consult [our security guide](https://github.com/tensorflow/tensorflow/blob/master/SECURITY.md) for more information regarding the security model and how to contact us with issues and questions.</p>
<p>### Attribution
This has been reported via Google OSS VRP.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-93vr-9q9m-pj8p"/>
  </entry>
</feed>
