CVE-2025-3136

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
CVSS

No CVSS.

References
Link Resource
https://github.com/ARPANET-cybersecurity/vuldb/issues/2 Not Applicable
https://github.com/pytorch/pytorch/issues/149821 Exploit Issue Tracking Vendor Advisory
https://github.com/pytorch/pytorch/issues/149821#issue-2940838975 Exploit Issue Tracking Vendor Advisory
https://github.com/pytorch/pytorch/issues/149821#issuecomment-2765311086 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.303041 Permissions Required VDB Entry
https://vuldb.com/?id.303041 Third Party Advisory VDB Entry
https://vuldb.com/?submit.525252 Third Party Advisory VDB Entry Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:pytorch:2.6.0:-:*:*:*:python:*:*

History

28 May 2025, 15:59

Type Values Removed Values Added
CWE CWE-787
References () https://github.com/ARPANET-cybersecurity/vuldb/issues/2 - () https://github.com/ARPANET-cybersecurity/vuldb/issues/2 - Not Applicable
References () https://github.com/pytorch/pytorch/issues/149821 - () https://github.com/pytorch/pytorch/issues/149821 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/pytorch/pytorch/issues/149821#issuecomment-2765311086 - () https://github.com/pytorch/pytorch/issues/149821#issuecomment-2765311086 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/pytorch/pytorch/issues/149821#issue-2940838975 - () https://github.com/pytorch/pytorch/issues/149821#issue-2940838975 - Exploit, Issue Tracking, Vendor Advisory
References () https://vuldb.com/?ctiid.303041 - () https://vuldb.com/?ctiid.303041 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.303041 - () https://vuldb.com/?id.303041 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.525252 - () https://vuldb.com/?submit.525252 - Third Party Advisory, VDB Entry, Exploit
First Time Linuxfoundation
Linuxfoundation pytorch
CPE cpe:2.3:a:linuxfoundation:pytorch:2.6.0:-:*:*:*:python:*:*

03 Apr 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 3.3
v2 : unknown
v3 : unknown
CWE CWE-119
References
  • () https://github.com/ARPANET-cybersecurity/vuldb/issues/2 -

03 Apr 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-03 04:15

Updated : 2025-05-28 15:59


NVD link : CVE-2025-3136

Mitre link : CVE-2025-3136


JSON object : View

Products Affected

linuxfoundation

  • pytorch
CWE
CWE-787

Out-of-bounds Write