Описание
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| pytorch | fixed | 2.12.0+dfsg2-1 | package | |
| pytorch | no-dsa | trixie | package | |
| pytorch | no-dsa | bookworm | package | |
| pytorch | postponed | bullseye | package |
Примечания
https://github.com/pytorch/pytorch/issues/149622
Fixed by: https://github.com/Nicoshev/pytorch/commit/494518046816d29099b7d056a74ffa5c244fdcdd
EPSS
Связанные уязвимости
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
EPSS