CVE-2022-45907
published 2022-11-26CVE-2022-45907: In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.19%
64.5th percentile
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pytorch | < pytorch 1.13.1+dfsg-1 (bookworm) | pytorch 1.13.1+dfsg-1 (bookworm) |
| linuxfoundation | pytorch | < 1.13.1 | 1.13.1 |
| linuxfoundation | pytorch | >= 0 < 1.13.1+dfsg-1 | 1.13.1+dfsg-1 |
| linuxfoundation | pytorch | >= 0 < 1.13.1+dfsg-1 | 1.13.1+dfsg-1 |
| linuxfoundation | pytorch | >= 0 < 1.13.1+dfsg-1 | 1.13.1+dfsg-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-45907: In PyTorch before trunk/89695, torch
osv·2022-11-26·CVSS 9.8
CVE-2022-45907 [CRITICAL] CVE-2022-45907: In PyTorch before trunk/89695, torch
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
OSV
PyTorch vulnerable to arbitrary code execution
osv·2022-11-26
CVE-2022-45907 [CRITICAL] PyTorch vulnerable to arbitrary code execution
PyTorch vulnerable to arbitrary code execution
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely. The fix for this issue is available in version 1.13.1. There is a release checker in [issue #89855](https://github.com/pytorch/pytorch/issues/89855).
GHSA
PyTorch vulnerable to arbitrary code execution
ghsa·2022-11-26
CVE-2022-45907 [CRITICAL] CWE-77 PyTorch vulnerable to arbitrary code execution
PyTorch vulnerable to arbitrary code execution
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely. The fix for this issue is available in version 1.13.1. There is a release checker in [issue #89855](https://github.com/pytorch/pytorch/issues/89855).
Debian
CVE-2022-45907: pytorch - In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause a...
vendor_debian·2022·CVSS 9.8
CVE-2022-45907 [CRITICAL] CVE-2022-45907: pytorch - In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause a...
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
Scope: local
bookworm: resolved (fixed in 1.13.1+dfsg-1)
bullseye: open
forky: resolved (fixed in 1.13.1+dfsg-1)
sid: resolved (fixed in 1.13.1+dfsg-1)
trixie: resolved (fixed in 1.13.1+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-26
Published