cbcvebase.

Linuxfoundation Pytorch vulnerabilities

31 known vulnerabilities affecting linuxfoundation/pytorch.

Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM15LOW3

Vulnerabilities

Page 1 of 2
CVE-2025-32434P2CRITICALCVSS 9.8fixed in 2.6.02025-04-18
CVE-2025-32434 [CRITICAL] CWE-502 CVE-2025-32434: PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep n PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2
nvdosv
CVE-2026-24747P3HIGHCVSS 8.8fixed in 2.10.02026-01-27
CVE-2026-24747 [HIGH] CWE-94 CVE-2026-24747: PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerabili PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fix
ghsanvdosv
CVE-2022-45907P3CRITICALCVSS 9.8fixed in 1.13.12022-11-26
CVE-2022-45907 [CRITICAL] CWE-94 CVE-2022-45907: In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execut In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
nvdosv
CVE-2024-48063P3CRITICALCVSS 9.8≤ 2.4.12024-10-29
CVE-2024-48063 [CRITICAL] CWE-502 CVE-2024-48063: In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple par In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
nvd
CVE-2026-4538P3HIGHCVSS 7.8v2.10.02026-03-22
CVE-2026-4538 [HIGH] CWE-20 CVE-2026-4538: A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request
nvd
CVE-2025-2148P3HIGHCVSS 7.5v2.6.0v2.6.0+cu1242025-03-10
CVE-2025-2148 [HIGH] CWE-119 CVE-2025-2148: A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather h
nvd
CVE-2025-55558P3HIGHCVSS 7.5≤ 2.7.02025-09-25
CVE-2025-55558 [HIGH] CWE-400 CVE-2025-55558: A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.n A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
nvd
CVE-2025-55552P3HIGHCVSS 7.5≤ 2.8.02025-09-25
CVE-2025-55552 [HIGH] CWE-190 CVE-2025-55552: pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and tor pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
nvd
CVE-2025-55557P3HIGHCVSS 7.5≤ 2.7.02025-09-25
CVE-2025-55557 [HIGH] CWE-248 CVE-2025-55557: A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
nvd
CVE-2025-55551P3HIGHCVSS 7.5≤ 2.8.02025-09-25
CVE-2025-55551 [HIGH] CWE-400 CVE-2025-55551: An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Se An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
nvd
CVE-2025-55560P3HIGHCVSS 7.5≤ 2.7.02025-09-25
CVE-2025-55560 [HIGH] CWE-400 CVE-2025-55560: An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of to An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
nvd
CVE-2024-31583P4HIGHCVSS 7.8fixed in 2.2.02024-04-17
CVE-2024-31583 [HIGH] CWE-416 CVE-2024-31583: Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
nvdosv
CVE-2025-55553P3HIGHCVSS 7.5≤ 2.7.02025-09-25
CVE-2025-55553 [HIGH] CWE-248 CVE-2025-55553: A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
nvd
CVE-2025-2999P4MEDIUMCVSS 5.3v2.6.02025-03-31
CVE-2025-2999 [MEDIUM] CWE-119 CVE-2025-2999: A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-2998P4MEDIUMCVSS 5.3v2.6.02025-03-31
CVE-2025-2998 [MEDIUM] CWE-119 CVE-2025-2998: A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulne A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-3001P4MEDIUMCVSS 5.3v2.6.02025-03-31
CVE-2025-3001 [MEDIUM] CWE-119 CVE-2025-3001: A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the fu A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-46152P4MEDIUMCVSS 5.3≥ 2.6.0, < 2.7.02025-09-25
CVE-2025-46152 [MEDIUM] CWE-787 CVE-2025-46152: In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds val In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
nvd
CVE-2025-46150P4MEDIUMCVSS 5.3≥ 2.6.0, < 2.7.02025-09-25
CVE-2025-46150 [MEDIUM] CVE-2025-46150: In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results. In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
nvd
CVE-2025-55554P4MEDIUMCVSS 5.3≤ 2.8.02025-09-25
CVE-2025-55554 [MEDIUM] CWE-190 CVE-2025-55554: pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
nvd
CVE-2025-3000P4MEDIUMCVSS 5.3v2.6.02025-03-31
CVE-2025-3000 [MEDIUM] CWE-119 CVE-2025-3000: A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function to A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
nvd
Linuxfoundation Pytorch vulnerabilities | cvebase