CVE-2023-25801: Double Free
(updated )
TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, nn_ops.fractional_avg_pool_v2
and nn_ops.fractional_max_pool_v2
require the first and fourth elements of their parameter pooling_ratio
to be equal to 1.0, as pooling on batch and channel dimensions is not supported. A fix is included in TensorFlow 2.12.0 and 2.11.1.
References
Detect and mitigate CVE-2023-25801 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →