Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4hp-rmr7-r7v8

Опубликовано: 31 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 4.8
CVSS3: 5.3

Описание

PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

Пакеты

Наименование

torch

pip
Затронутые версииВерсия исправления

<= 2.6.0

Отсутствует

EPSS

Процентиль: 9%
0.00189
Низкий

4.8 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
nvd
больше 1 года назад

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

msrc
12 дней назад

PyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruption

CVSS3: 5.3
debian
больше 1 года назад

A vulnerability was found in PyTorch 2.6.0. It has been declared as cr ...

EPSS

Процентиль: 9%
0.00189
Низкий

4.8 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119