CVE-2025-2953
A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124.
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.26% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- linuxfoundation/pytorch
- Source
- cna@vuldb.com
References
- https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models
- https://github.com/pytorch/pytorch/issues/149274Exploit, Issue Tracking
- https://github.com/pytorch/pytorch/issues/149274#issue-2923122269Exploit, Issue Tracking
- https://vuldb.com/?ctiid.302006Permissions Required, VDB Entry
- https://vuldb.com/?id.302006Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.521279Third Party Advisory, VDB Entry
- https://github.com/pytorch/pytorch/issues/149274Exploit, Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.