Msrc Azl3 Pytorch 2.2.2-12 On Azure Linux 3.0 vulnerabilities
5 known vulnerabilities affecting msrc/azl3_pytorch_2.2.2-12_on_azure_linux_3.0.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-34445HIGHCVSS 8.62026-04-02
CVE-2026-34445 [HIGH] CWE-20 ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
msrc
CVE-2026-34446MEDIUMCVSS 4.72026-04-02
CVE-2026-34446 [MEDIUM] CWE-22 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
msrc
CVE-2025-55551HIGHCVSS 7.52025-09-09
CVE-2025-55551 [HIGH] An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our cust
msrc
CVE-2025-55554MEDIUMCVSS 5.32025-09-09
CVE-2025-55554 [MEDIUM] CWE-190 pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it
msrc
CVE-2025-51480HIGHCVSS 8.82025-07-08
CVE-2025-51480 [HIGH] CWE-22 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing t
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.
FAQ: I
msrc