A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
References
Link | Resource |
---|---|
https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models | |
https://github.com/pytorch/pytorch/issues/149274 | Exploit Issue Tracking |
https://github.com/pytorch/pytorch/issues/149274#issue-2923122269 | Exploit Issue Tracking |
https://vuldb.com/?ctiid.302006 | Permissions Required VDB Entry |
https://vuldb.com/?id.302006 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.521279 | Third Party Advisory VDB Entry |
https://github.com/pytorch/pytorch/issues/149274 | Exploit Issue Tracking |
Configurations
History
22 Apr 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | (en) A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects. |
15 Apr 2025, 17:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Linuxfoundation pytorch
Linuxfoundation |
|
CPE | cpe:2.3:a:linuxfoundation:pytorch:2.6.0\+cu124:*:*:*:*:python:*:* | |
References | () https://github.com/pytorch/pytorch/issues/149274 - Exploit, Issue Tracking | |
References | () https://github.com/pytorch/pytorch/issues/149274#issue-2923122269 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?ctiid.302006 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.302006 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.521279 - Third Party Advisory, VDB Entry |
01 Apr 2025, 20:26
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
31 Mar 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/pytorch/pytorch/issues/149274 - |
30 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-30 16:15
Updated : 2025-04-22 12:15
NVD link : CVE-2025-2953
Mitre link : CVE-2025-2953
CVE.ORG link : CVE-2025-2953
JSON object : View
Products Affected
linuxfoundation
- pytorch
CWE
CWE-404
Improper Resource Shutdown or Release