A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
References
Link | Resource |
---|---|
https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models | |
https://github.com/pytorch/pytorch/issues/149274 | Exploit Issue Tracking |
https://github.com/pytorch/pytorch/issues/149274 | Exploit Issue Tracking |
https://github.com/pytorch/pytorch/issues/149274#issue-2923122269 | Exploit Issue Tracking |
https://vuldb.com/?ctiid.302006 | Permissions Required VDB Entry |
https://vuldb.com/?id.302006 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.521279 | Third Party Advisory VDB Entry |
Configurations
History
22 Apr 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects. | |
References |
|
15 Apr 2025, 17:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Linuxfoundation
Linuxfoundation pytorch |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
References | () https://vuldb.com/?id.302006 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?ctiid.302006 - Permissions Required, VDB Entry | |
References | () https://github.com/pytorch/pytorch/issues/149274 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?submit.521279 - Third Party Advisory, VDB Entry | |
References | () https://github.com/pytorch/pytorch/issues/149274#issue-2923122269 - Exploit, Issue Tracking | |
CPE | cpe:2.3:a:linuxfoundation:pytorch:2.6.0\+cu124:*:*:*:*:python:*:* |
31 Mar 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
CWE | ||
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
30 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-30 16:15
Updated : 2025-04-22 12:15
NVD link : CVE-2025-2953
Mitre link : CVE-2025-2953
JSON object : View
Products Affected
linuxfoundation
- pytorch
CWE
No CWE.