Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3749-ghw9-m3mg

Опубликовано: 30 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.9
CVSS3: 3.3

Описание

PyTorch susceptible to local Denial of Service

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

Пакеты

Наименование

torch

pip
Затронутые версииВерсия исправления

< 2.7.1-rc1

2.7.1-rc1

EPSS

Процентиль: 19%
0.0006
Низкий

1.9 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 3.3
ubuntu
5 месяцев назад

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.

CVSS3: 3.3
redhat
5 месяцев назад

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.

CVSS3: 3.3
nvd
5 месяцев назад

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.

CVSS3: 5.5
msrc
3 месяца назад

Описание отсутствует

CVSS3: 3.3
debian
5 месяцев назад

A vulnerability, which was classified as problematic, has been found i ...

EPSS

Процентиль: 19%
0.0006
Низкий

1.9 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-404