Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-2148

Опубликовано: 10 мар. 2025
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pytorchunfixedpackage
pytorchno-dsatrixiepackage
pytorchno-dsabookwormpackage
pytorchpostponedbullseyepackage

Примечания

  • https://github.com/pytorch/pytorch/issues/147722

EPSS

Процентиль: 36%
0.00428
Низкий

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.

CVSS3: 5
nvd
больше 1 года назад

A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.

CVSS3: 5
github
больше 1 года назад

PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument

EPSS

Процентиль: 36%
0.00428
Низкий