PT-2025-39423 · Facebook+1 · Pytorch+1

Published

2025-04-17

·

Updated

2025-12-06

·

CVE-2025-55560

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions pytorch version 2.7.0
Description A flaw exists in pytorch that can result in a Denial of Service (DoS). This occurs when a PyTorch model incorporates both torch.Tensor.to sparse() and torch.Tensor.to dense() and is compiled using Inductor. The issue is related to the interaction between sparse and dense tensor conversions during compilation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

AZL-67944
AZL-67968
BDU:2025-12837
BIT-PYTORCH-2025-55560
CVE-2025-55560
PYSEC-2025-209

Affected Products

Debian
Pytorch