Debian Pytorch vulnerabilities
5 known vulnerabilities affecting debian/pytorch.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-32434P2CRITICALCVSS 9.3fixed in pytorch 1.7.1-7+deb11u1 (bullseye)2025
CVE-2025-32434 [CRITICAL] CVE-2025-32434: pytorch - PyTorch is a Python package that provides tensor computation with strong GPU acc...
PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.
Scope: lo
debian
CVE-2022-45907P3CRITICALCVSS 9.8fixed in pytorch 1.13.1+dfsg-1 (bookworm)2022
CVE-2022-45907 [CRITICAL] CVE-2022-45907: pytorch - In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause a...
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
Scope: local
bookworm: resolved (fixed in 1.13.1+dfsg-1)
bullseye: open
forky: resolved (fixed in 1.13.1+dfsg-1)
sid: resolved (fixed in 1.13.1+dfsg-1)
trixie: resolved (fixed in 1.13.1+dfsg-1)
debian
CVE-2024-31583P4HIGHCVSS 7.8fixed in pytorch 2.4.1-1 (forky)2024
CVE-2024-31583 [HIGH] CVE-2024-31583: pytorch - Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnera...
Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.4.1-1)
sid: resolved (fixed in 2.4.1-1)
trixie: resolved (fixed in 2.4.1-1)
debian
CVE-2024-31584P4MEDIUMCVSS 5.5fixed in pytorch 2.4.1-1 (forky)2024
CVE-2024-31584 [MEDIUM] CVE-2024-31584: pytorch - Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component ...
Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 2.4.1-1)
sid: resolved (fixed in 2.4.1-1)
trixie: resolved (fixed in 2.4.1-1)
debian
CVE-2024-31580P4MEDIUMCVSS 4.0fixed in pytorch 2.4.1-1 (forky)2024
CVE-2024-31580 [MEDIUM] CVE-2024-31580: pytorch - PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerabi...
PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.4.1-1)
sid: resolved (fixed in 2.4.1-1)
trixie: resolved (fixed in 2.4
debian