PT-2024-5965 · Pytorch+1 · Pytorch+1

Published

2024-04-17

·

Updated

2025-06-11

·

CVE-2024-31583

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pytorch versions prior to v2.2.0
Description The issue is related to a use-after-free vulnerability in the torch/csrc/jit/mobile/interpreter.cpp component of the PyTorch machine learning framework. This vulnerability can be exploited to execute arbitrary code. The vulnerability is associated with the use of memory after it has been freed.
Recommendations For versions prior to v2.2.0, update to version v2.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the torch/csrc/jit/mobile/interpreter.cpp component until a patch is available.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

AZL-39942
BDU:2024-06772
BIT-PYTORCH-2024-31583
CVE-2024-31583
GHSA-PG7H-5QX3-WJR3
PYSEC-2024-251

Affected Products

Debian
Pytorch