Msrc Cbl2 Pytorch 2.0.0-11 On Cbl Mariner 2.0 vulnerabilities

6 known vulnerabilities affecting msrc/cbl2_pytorch_2.0.0-11_on_cbl_mariner_2.0.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-55560HIGHCVSS 7.52025-09-09
CVE-2025-55560 [HIGH] CWE-400 An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor. An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potent
msrc
CVE-2025-55551HIGHCVSS 7.52025-09-09
CVE-2025-55551 [HIGH] An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our cust
msrc
CVE-2025-55554MEDIUMCVSS 5.32025-09-09
CVE-2025-55554 [MEDIUM] CWE-190 pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it
msrc
CVE-2025-55552MEDIUMCVSS 5.32025-09-09
CVE-2025-55552 [HIGH] CWE-190 pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together. pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to
msrc
CVE-2025-51480HIGHCVSS 8.82025-07-08
CVE-2025-51480 [HIGH] CWE-22 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing t Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions. FAQ: I
msrc
CVE-2025-3001MEDIUMCVSS 5.32025-03-11
CVE-2025-3001 [MEDIUM] CWE-119 PyTorch torch.lstm_cell memory corruption PyTorch torch.lstm_cell memory corruption Mariner: Mariner VulDB: VulDB Customer Action Required: Yes Remediation: CBL-Mariner Releases Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
msrc