CVE-2025-2953

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
Configurations

Configuration 1 (hide)

cpe:2.3:a:linuxfoundation:pytorch:2.6.0\+cu124:*:*:*:*:python:*:*

History

22 Apr 2025, 12:15

Type Values Removed Values Added
References
  • () https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models -
Summary (en) A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. (en) A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.

15 Apr 2025, 17:55

Type Values Removed Values Added
First Time Linuxfoundation pytorch
Linuxfoundation
CPE cpe:2.3:a:linuxfoundation:pytorch:2.6.0\+cu124:*:*:*:*:python:*:*
References () https://github.com/pytorch/pytorch/issues/149274 - () https://github.com/pytorch/pytorch/issues/149274 - Exploit, Issue Tracking
References () https://github.com/pytorch/pytorch/issues/149274#issue-2923122269 - () https://github.com/pytorch/pytorch/issues/149274#issue-2923122269 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.302006 - () https://vuldb.com/?ctiid.302006 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.302006 - () https://vuldb.com/?id.302006 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.521279 - () https://vuldb.com/?submit.521279 - Third Party Advisory, VDB Entry

01 Apr 2025, 20:26

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como problemática en PyTorch 2.6.0+cu124. La función torch.mkldnn_max_pool2d se ve afectada por este problema. La manipulación provoca una denegación de servicio. Un ataque debe abordarse localmente. Se ha hecho público el exploit y puede que sea utilizado.

31 Mar 2025, 13:15

Type Values Removed Values Added
References () https://github.com/pytorch/pytorch/issues/149274 - () https://github.com/pytorch/pytorch/issues/149274 -

30 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-30 16:15

Updated : 2025-04-22 12:15


NVD link : CVE-2025-2953

Mitre link : CVE-2025-2953

CVE.ORG link : CVE-2025-2953


JSON object : View

Products Affected

linuxfoundation

  • pytorch
CWE
CWE-404

Improper Resource Shutdown or Release