Skip to main content

Vendor/product archive

linuxfoundation / pytorch CVEs

Beta · best-effort

31 CVEs tagged to linuxfoundation / pytorch3 Critical, 8 High, 16 Medium, 4 Low, 0 Unrated.

CVE-2026-4538

Published Mar 22, 2026

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-24747

Published Jan 27, 2026

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a maliciou…

CVSS 8.8 · High
evidence mentions
8
Buzz score
39.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-63396

Published Nov 12, 2025

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-55560

Published Sep 25, 2025

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55558

Published Sep 25, 2025

A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by In…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55557

Published Sep 25, 2025

A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55554

Published Sep 25, 2025

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-55553

Published Sep 25, 2025

A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55551

Published Sep 25, 2025

An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-46153

Published Sep 25, 2025

PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dro…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46152

Published Sep 25, 2025

In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46150

Published Sep 25, 2025

In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46148

Published Sep 25, 2025

In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32434

Published Apr 18, 2025

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prio…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-3730

Published Apr 16, 2025

A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cp…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3136

Published Apr 3, 2025

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/c…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3121

Published Apr 2, 2025

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corrupti…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3001

Published Mar 31, 2025

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3000

Published Mar 31, 2025

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2999

Published Mar 31, 2025

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to mem…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2998

Published Mar 31, 2025

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulati…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2953

Published Mar 30, 2025

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2149

Published Mar 10, 2025

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. T…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2