Home » Database

AVID-2026-R1202

Description

TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize (CVE-2023-25670)

Details

TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

Reason for inclusion in AVID: CVE-2023-25670 describes a null pointer dereference in TensorFlow’s QuantizedMatMulWithBiasAndDequantize when MKL is enabled, affecting TensorFlow versions before 2.12.0 and 2.11.1. The vulnerability impacts availability (A) with a network attack vector (AV:N) and no authentication required, indicating a security risk. TensorFlow is a core AI framework used to build, train, and deploy general-purpose AI systems, placing this vulnerability squarely in the software supply chain for AI workflows. The advisory provides concrete fix versions and references, supplying sufficient evidence for classification.

References

Affected or Relevant Artifacts

  • Developer: tensorflow
  • Deployer: tensorflow
  • Artifact Details:
TypeName
Systemtensorflow

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score7.5
Base Severity🔴 High
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability Impact🔴 High

CWE

IDDescription
CWE-476CWE-476: NULL Pointer Dereference

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2023-03-24
  • Version: 0.3.3
  • AVID Entry