Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgrw-7cvw-pwgx

Опубликовано: 31 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 4.8
CVSS3: 5.3

Описание

PyTorch is vulnerable to memory corruption through its unpack_sequence function

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

A patch is available through commit 4945180.

Пакеты

Наименование

torch

pip
Затронутые версииВерсия исправления

< 2.9.1

2.9.1

EPSS

Процентиль: 10%
0.00198
Низкий

4.8 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
nvd
больше 1 года назад

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
debian
больше 1 года назад

A vulnerability was found in PyTorch 2.6.0. It has been rated as criti ...

EPSS

Процентиль: 10%
0.00198
Низкий

4.8 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-119