canonical / canonical/tensorflow-rock
Vulnerabilities found for tensorflow:2.5.1
- Dominant language
- Python
- Stars
- 1
- Forks
- 0
- Avg merge
- 7h 20m
- Merged PRs (30d)
- 1
Description
## Vulnerabilities found for tensorflow:2.5.1
```
For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://aquasecurity.github.io/trivy/v0.56/docs/supply-chain/vex/repo#publishing-vex-documents
To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.
charmedkubeflow/tensorflow:2.5.1-1d84aaf (ubuntu 24.04)
=======================================================
Total: 0 (HIGH: 0, CRITICAL: 0)
Python (python-pkg)
===================
Total: 77 (HIGH: 74, CRITICAL: 3)
┌───────────────────────────┬─────────────────────┬──────────┬────────┬───────────────────┬────────────────────────────────┬──────────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├───────────────────────────┼─────────────────────┼──────────┼────────┼───────────────────┼────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ grpcio (METADATA) │ CVE-2023-33953 │ HIGH │ fixed │ 1.34.1 │ 1.53.2, 1.54.3, 1.55.2, 1.56.2 │ gRPC: hpack table accounting errors can lead to denial of │
│ │ │ │ │ │ │ service │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-33953 │
├───────────────────────────┼─────────────────────┤ │ ├───────────────────┼────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ protobuf (METADATA) │ CVE-2025-4565 │ │ │ 3.20.3 │ 4.25.8, 5.29.5, 6.31.1 │ python-protobuf: Unbounded recursion in Python Protobuf │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2025-4565 │
├───────────────────────────┼─────────────────────┼──────────┤ ├───────────────────┼────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ tensorflow-cpu (METADATA) │ CVE-2021-41208 │ CRITICAL │ │ 2.5.1 │ 2.6.1, 2.5.2, 2.4.4 │ Incomplete validation in boosted trees code │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41208 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25668 │ │ │ │ 2.11.1 │ CVE-2023-25668 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25668 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ GHSA-h6gw-r52c-724r │ │ │ │ 2.5.3, 2.6.3, 2.7.1 │ NULL Pointer Dereference and Access of Uninitialized Pointer │
│ │ │ │ │ │ │ in TensorFlow │
│ │ │ │ │ │ │ https://github.com/advisories/GHSA-h6gw-r52c-724r │
│ ├─────────────────────┼──────────┤ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2021-41201 │ HIGH │ │ │ 2.6.1, 2.5.2, 2.4.4 │ Unitialized access in `EinsumHelper::ParseEquation` │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41201 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2021-41203 │ │ │ │ │ Missing validation during checkpoint loading │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41203 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2021-41206 │ │ │ │ │ Incomplete validation of shapes in multiple TF ops │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41206 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2021-41210 │ │ │ │ │ Heap OOB read in `tf.raw_ops.SparseCountSparseOutput` │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41210 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2021-41212 │ │ │ │ │ Heap OOB read in `tf.ragged.cross` │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41212 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2021-41214 │ │ │ │ │ Reference binding to `nullptr` in `tf.ragged.cross` │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41214 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2021-41219 │ │ │ │ │ Undefined behavior via `nullptr` reference binding in sparse │
│ │ │ │ │ │ │ matrix multiplication │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41219 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2021-41221 │ │ │ │ │ Access to invalid memory during shape inference in `Cudnn*` │
│ │ │ │ │ │ │ ops │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2021-41221 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21726 │ │ │ │ 2.5.3, 2.6.3, 2.7.1 │ Out of bounds read in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21726 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21727 │ │ │ │ │ Integer overflow in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21727 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21728 │ │ │ │ │ Out of bounds read in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21728 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21729 │ │ │ │ │ Overflow and uncaught divide by zero in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21729 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21730 │ │ │ │ │ Out of bounds read in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21730 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21731 │ │ │ │ │ Type confusion leading to segfault in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21731 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21734 │ │ │ │ │ `CHECK`-failures in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21734 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21735 │ │ │ │ │ Division by zero in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21735 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21736 │ │ │ │ │ Undefined behavior in `SparseTensorSliceDataset` │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21736 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21737 │ │ │ │ │ Assertion failure based denial of service in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21737 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21738 │ │ │ │ │ Integer overflow leading to crash in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21738 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21739 │ │ │ │ │ Null pointer dereference in TensorFlow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21739 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21740 │ │ │ │ │ Heap overflow in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21740 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-21741 │ │ │ │ │ Division by zero in TFLite │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-21741 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23557 │ │ │ │ │ Division by zero in TFLite │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23557 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23558 │ │ │ │ │ Integer overflow in TFLite array creation │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23558 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23559 │ │ │ │ │ Integer overflow in TFLite │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23559 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23560 │ │ │ │ │ Read and Write outside of bounds in TensorFlow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23560 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23561 │ │ │ │ │ Out of bounds write in TFLite │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23561 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23562 │ │ │ │ │ Integer overflow in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23562 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23563 │ │ │ │ │ Insecure temporary file in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23563 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23564 │ │ │ │ │ Reachable Assertion in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23564 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23565 │ │ │ │ │ `CHECK`-failures in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23565 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23566 │ │ │ │ │ Out of bounds write in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23566 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23567 │ │ │ │ │ Integer overflows in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23567 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23568 │ │ │ │ │ Integer overflows in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23568 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23569 │ │ │ │ │ `CHECK`-fails when building invalid tensor shapes in │
│ │ │ │ │ │ │ Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23569 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23570 │ │ │ │ │ Null-dereference in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23570 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23571 │ │ │ │ │ Reachable Assertion in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23571 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23572 │ │ │ │ │ Crash when type cannot be specialized in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23572 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23573 │ │ │ │ │ Uninitialized variable access in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23573 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23574 │ │ │ │ │ Out of bounds read and write in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23574 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23575 │ │ │ │ │ Integer overflow in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23575 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23576 │ │ │ │ │ Integer overflow in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23576 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23577 │ │ │ │ │ Null-dereference in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23577 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23584 │ │ │ │ │ Use after free in `DecodePng` kernel │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23584 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23587 │ │ │ │ │ Integer overflow in TensorFlow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23587 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-23591 │ │ │ │ │ Stack overflow in TensorFlow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-23591 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-29208 │ │ │ │ 2.6.4, 2.7.2, 2.8.1 │ Segfault and OOB write due to incomplete validation in │
│ │ │ │ │ │ │ `EditDistance` in TensorFlow... │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-29208 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-29216 │ │ │ │ │ Code injection in `saved_model_cli` in TensorFlow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-29216 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-35937 │ │ │ │ 2.7.2, 2.8.1, 2.9.1 │ TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-35937 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-35939 │ │ │ │ │ TensorFlow vulnerable to OOB write in `scatter_nd` in TF │
│ │ │ │ │ │ │ Lite │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-35939 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-41900 │ │ │ │ 2.8.4, 2.9.3, 2.10.1 │ CVE-2022-41900 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.0-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-41900 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2022-41902 │ │ │ │ │ Out of bounds write in grappler in Tensorflow │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-41902 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25658 │ │ │ │ 2.11.1 │ CVE-2023-25658 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25658 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25659 │ │ │ │ │ CVE-2023-25659 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25659 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25660 │ │ │ │ │ CVE-2023-25660 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25660 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25662 │ │ │ │ │ CVE-2023-25662 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25662 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25663 │ │ │ │ │ CVE-2023-25663 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25663 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25664 │ │ │ │ │ CVE-2023-25664 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25664 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25665 │ │ │ │ │ CVE-2023-25665 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25665 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25666 │ │ │ │ │ CVE-2023-25666 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25666 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25669 │ │ │ │ │ CVE-2023-25669 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25669 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25670 │ │ │ │ │ CVE-2023-25670 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25670 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25671 │ │ │ │ │ CVE-2023-25671 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25671 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25672 │ │ │ │ │ CVE-2023-25672 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25672 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25673 │ │ │ │ │ CVE-2023-25673 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25673 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25674 │ │ │ │ │ CVE-2023-25674 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25674 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25675 │ │ │ │ │ CVE-2023-25675 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25675 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25676 │ │ │ │ │ CVE-2023-25676 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25676 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-25801 │ │ │ │ │ CVE-2023-25801 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-25801 │
│ ├─────────────────────┤ │ │ │ ├──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-27579 │ │ │ │ │ CVE-2023-27579 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-1 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-27579 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ CVE-2023-33976 │ │ │ │ 2.12.1 │ CVE-2023-33976 affecting package tensorflow for versions │
│ │ │ │ │ │ │ less than 2.11.1-2 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2023-33976 │
│ ├─────────────────────┤ │ │ ├────────────────────────────────┼──────────────────────────────────────────────────────────────┤
│ │ GHSA-43q8-3fv7-pr5x │ │ │ │ 2.5.3, 2.6.3, 2.7.1 │ Improper Validation of Integrity Check Value in TensorFlow │
│ │ │ │ │ │ │ https://github.com/advisories/GHSA-43q8-3fv7-pr5x │
└───────────────────────────┴─────────────────────┴──────────┴────────┴───────────────────┴────────────────────────────────┴──────────────────────────────────────────────────────────────┘
```
Details: https://github.com/canonical/tensorflow-rock/actions/runs/18732321676
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the repository's dependency and image-build definitions for the tensorflow:2.5.1 rock, then compare the pinned Python packages with the fixed versions listed in the report. Re-run the vulnerability scan against the rebuilt image; done means the reported vulnerabilities are resolved or explicitly assessed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python, tensorflow
- Domain
- machine-learning, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100