PT-2025-10576 · Pytorch+1 · Pytorch+1

Default436352

·

Published

2025-03-10

·

Updated

2026-02-26

·

CVE-2025-2148

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PyTorch version 2.6.0+cu124
Description A critical vulnerability was found in the function torch.ops.profiler. call end callbacks on jit fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely, and the complexity of an attack is rather high. The exploitation appears to be difficult.
Recommendations As a temporary workaround, consider disabling the torch.ops.profiler. call end callbacks on jit fut function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BIT-PYTORCH-2025-2148
CVE-2025-2148
PYSEC-2025-189

Affected Products

Debian
Pytorch