cbcvebase.

Linuxfoundation Pytorch vulnerabilities

31 known vulnerabilities affecting linuxfoundation/pytorch.

Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM15LOW3

Vulnerabilities

Page 2 of 2
CVE-2024-31584P4MEDIUMCVSS 5.5fixed in 2.2.02024-04-19
CVE-2024-31584 [MEDIUM] CWE-125 CVE-2024-31584: Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobil Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
nvdosv
CVE-2025-46153P4MEDIUMCVSS 5.3≥ 2.6.0, < 2.7.02025-09-25
CVE-2025-46153 [MEDIUM] CWE-1176 CVE-2025-46153: PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
nvd
CVE-2025-46148P4MEDIUMCVSS 5.3≤ 2.6.02025-09-25
CVE-2025-46148 [MEDIUM] CVE-2025-46148: In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results. In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
nvd
CVE-2025-3121P4MEDIUMCVSS 5.5v2.6.02025-04-02
CVE-2025-3121 [MEDIUM] CWE-119 CVE-2025-3121: A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-2953P4MEDIUMCVSS 5.5v2.6.0\+cu124v2.6.0+cu1242025-03-30
CVE-2025-2953 [MEDIUM] CWE-404 CVE-2025-2953: A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affecte A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still
nvd
CVE-2025-46149P4MEDIUMCVSS 5.3≥ 2.6.0, < 2.7.02025-09-25
CVE-2025-46149 [MEDIUM] CWE-617 CVE-2025-46149: In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error. In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
nvd
CVE-2025-3730P4MEDIUMCVSS 5.5v2.6.02025-04-16
CVE-2025-3730 [MEDIUM] CWE-404 CVE-2025-3730: A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the fu A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of th
nvd
CVE-2024-31580P4MEDIUMCVSS 4.0fixed in 2.2.02024-04-17
CVE-2024-31580 [MEDIUM] CWE-122 CVE-2024-31580: PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the componen PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvdosv
CVE-2025-3136P4LOWCVSS 3.3v2.6.02025-04-03
CVE-2025-3136 [LOW] CWE-119 CVE-2025-3136: A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue af A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-2149P4LOWCVSS 2.5v2.6.0v2.6.0+cu1242025-03-10
CVE-2025-2149 [LOW] CWE-665 CVE-2025-2149: A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exp
nvd
CVE-2025-63396P4LOWCVSS 3.3v2.5.0v2.7.12025-11-12
CVE-2025-63396 [LOW] CWE-667 CVE-2025-63396: An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.prof An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).
nvd
Linuxfoundation Pytorch vulnerabilities | cvebase