CVE-2025-2148
published 2025-03-10CVE-2025-2148: A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function…
PriorityP342high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.40%
32.5th percentile
A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pytorch | — | — |
| linuxfoundation | pytorch | — | — |
| linuxfoundation | pytorch | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv2.3LOW
vendor_debian2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-2148: A vulnerability was found in PyTorch 2
osv·2025-03-10·CVSS 2.3
CVE-2025-2148 [LOW] CVE-2025-2148: A vulnerability was found in PyTorch 2
A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
GHSA
GHSA-c678-jfcj-6jmf: A vulnerability was found in PyTorch 2
ghsa_unreviewed·2025-03-10
CVE-2025-2148 [LOW] CWE-119 GHSA-c678-jfcj-6jmf: A vulnerability was found in PyTorch 2
A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
GHSA
PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
ghsa·2025-03-10
CVE-2025-2148 [LOW] CWE-119 PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
Debian
CVE-2025-2148: pytorch - A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critic...
vendor_debian·2025·CVSS 2.3
CVE-2025-2148 [LOW] CVE-2025-2148: pytorch - A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critic...
A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-10
Published