PT-2025-32324 · Unknown · Executorch

Published

2025-08-07

·

Updated

2025-08-13

·

CVE-2025-54952

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ExecuTorch versions prior to commit 8f062d3f661e20bb19b24b767b9a9a46e8359f2b
Description An integer overflow in the loading of ExecuTorch models can lead to the allocation of smaller-than-expected memory regions. This can potentially result in code execution or other undesirable effects.
Recommendations Update ExecuTorch to a version after commit 8f062d3f661e20bb19b24b767b9a9a46e8359f2b.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-54952
GHSA-33R8-VRX9-RMCV

Affected Products

Executorch