Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qfhq-4f3w-5fph

Опубликовано: 31 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.9
CVSS3: 5.3

Описание

PyTorch is vulnerable to memory corruption through its torch.lstm_cell function

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

A patch is available through commit 999d94b.

Пакеты

Наименование

torch

pip
Затронутые версииВерсия исправления

< 2.10.0

2.10.0

EPSS

Процентиль: 9%
0.00189
Низкий

1.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
nvd
больше 1 года назад

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
msrc
8 месяцев назад

PyTorch torch.lstm_cell memory corruption

CVSS3: 5.3
debian
больше 1 года назад

A vulnerability classified as critical was found in PyTorch 2.6.0. Thi ...

EPSS

Процентиль: 9%
0.00189
Низкий

1.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119