Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xhgh-4jhq-chj3

Опубликовано: 23 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 7.1

Описание

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.

EPSS

Процентиль: 24%
0.00312
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.1
ubuntu
11 дней назад

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.

CVSS3: 7.1
nvd
11 дней назад

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.

CVSS3: 7.1
debian
11 дней назад

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains ...

EPSS

Процентиль: 24%
0.00312
Низкий

7.1 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-125