<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:54:57 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-25666 — TensorFlow has Floating Point Exception in AudioSpectrogram</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-25666</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; tensorflow&lt;/p&gt;
&lt;p&gt;TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, there is a floating point exception in AudioSpectrogram. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-25666</guid>
    </item>
    <item>
      <title>GHSA-f637-vh3r-vfh2 — TensorFlow has Floating Point Exception in AudioSpectrogram</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f637-vh3r-vfh2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact
version:2.11.0 //core/ops/audio_ops.cc:70&lt;/p&gt;
&lt;p&gt;Status SpectrogramShapeFn(InferenceContext* c) { ShapeHandle input; TF_RETURN_IF_ERROR(c-&amp;gt;WithRank(c-&amp;gt;input(0), 2, &amp;amp;input)); int32_t window_size; TF_RETURN_IF_ERROR(c-&amp;gt;GetAttr(&amp;#34;window_size&amp;#34;, &amp;amp;window_size)); int32_t stride; TF_RETURN_IF_ERROR(c-&amp;gt;GetAttr(&amp;#34;stride&amp;#34;, &amp;amp;stride)); .....[1]&lt;/p&gt;
&lt;p&gt;DimensionHandle input_length = c-&amp;gt;Dim(input, 0); DimensionHandle input_channels = c-&amp;gt;Dim(input, 1);&lt;/p&gt;
&lt;p&gt;DimensionHandle output_length; if (!c-&amp;gt;ValueKnown(input_length)) { output_length = c-&amp;gt;UnknownDim(); } else { const int64_t input_length_value = c-&amp;gt;Value(input_length); const int64_t length_minus_window = (input_length_value - window_size); int64_t output_length_value; if (length_minus_window &amp;lt; 0) { output_length_value = 0; } else { output_length_value = 1 + (length_minus_window / stride); .....[2] } output_length = c-&amp;gt;MakeDim(output_length_value); }&lt;/p&gt;
&lt;p&gt;Get the value of stride at [1], and the used at [2]
```python
import tensorflow as tf&lt;/p&gt;
&lt;p&gt;para = {&amp;#39;input&amp;#39;: tf.constant([[14.], [24.]], dtype=tf.float32), &amp;#39;window_size&amp;#39;: 1, &amp;#39;stride&amp;#39;: 0, &amp;#39;magnitude_squared&amp;#39;: False}
func = tf.raw_ops.AudioSpectrogram&lt;/p&gt;
&lt;p&gt;@tf.function(jit_compile=True)
def fuzz_jit():
   y = func(**para)
   return y&lt;/p&gt;
&lt;p&gt;fuzz_jit()
```&lt;/p&gt;
&lt;p&gt;### Patches
We have patched the issue in GitHub commit [d0d4e779da0d0f56499c6fa5ba09f0a576cc6b14](https://github.com/tensorflow/tensorflow/commit/d0d4e779da0d0f56499c6fa5ba09f0a576cc6b14).&lt;/p&gt;
&lt;p&gt;The fix will be included in TensorFlow 2.12.0. We will also cherrypick th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tensorflow, PyPI: tensorflow-cpu, PyPI: tensorflow-gpu&lt;/p&gt;
&lt;p&gt;### Impact
version:2.11.0 //core/ops/audio_ops.cc:70&lt;/p&gt;
&lt;p&gt;Status SpectrogramShapeFn(InferenceContext* c) { ShapeHandle input; TF_RETURN_IF_ERROR(c-&amp;gt;WithRank(c-&amp;gt;input(0), 2, &amp;amp;input)); int32_t window_size; TF_RETURN_IF_ERROR(c-&amp;gt;GetAttr(&amp;#34;window_size&amp;#34;, &amp;amp;window_size)); int32_t stride; TF_RETURN_IF_ERROR(c-&amp;gt;GetAttr(&amp;#34;stride&amp;#34;, &amp;amp;stride)); .....[1]&lt;/p&gt;
&lt;p&gt;DimensionHandle input_length = c-&amp;gt;Dim(input, 0); DimensionHandle input_channels = c-&amp;gt;Dim(input, 1);&lt;/p&gt;
&lt;p&gt;DimensionHandle output_length; if (!c-&amp;gt;ValueKnown(input_length)) { output_length = c-&amp;gt;UnknownDim(); } else { const int64_t input_length_value = c-&amp;gt;Value(input_length); const int64_t length_minus_window = (input_length_value - window_size); int64_t output_length_value; if (length_minus_window &amp;lt; 0) { output_length_value = 0; } else { output_length_value = 1 + (length_minus_window / stride); .....[2] } output_length = c-&amp;gt;MakeDim(output_length_value); }&lt;/p&gt;
&lt;p&gt;Get the value of stride at [1], and the used at [2]
```python
import tensorflow as tf&lt;/p&gt;
&lt;p&gt;para = {&amp;#39;input&amp;#39;: tf.constant([[14.], [24.]], dtype=tf.float32), &amp;#39;window_size&amp;#39;: 1, &amp;#39;stride&amp;#39;: 0, &amp;#39;magnitude_squared&amp;#39;: False}
func = tf.raw_ops.AudioSpectrogram&lt;/p&gt;
&lt;p&gt;@tf.function(jit_compile=True)
def fuzz_jit():
   y = func(**para)
   return y&lt;/p&gt;
&lt;p&gt;fuzz_jit()
```&lt;/p&gt;
&lt;p&gt;### Patches
We have patched the issue in GitHub commit [d0d4e779da0d0f56499c6fa5ba09f0a576cc6b14](https://github.com/tensorflow/tensorflow/commit/d0d4e779da0d0f56499c6fa5ba09f0a576cc6b14).&lt;/p&gt;
&lt;p&gt;The fix will be included in TensorFlow 2.12.0. We will also cherrypick th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f637-vh3r-vfh2</guid>
    </item>
  </channel>
</rss>
