MEDIUM 5.5
PYSEC-2025-191
상세
A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
PyPI / torch
최초 영향 버전:
0 No fixed version published yet for torch (pip). Pin to a known-safe version or switch to an alternative.
참고
- https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models [WEB]
- https://vuldb.com/?id.302006 [ADVISORY]
- https://vuldb.com/?submit.521279 [ADVISORY]
- https://github.com/pytorch/pytorch/issues/149274 [REPORT]
- https://github.com/pytorch/pytorch/issues/149274#issue-2923122269 [REPORT]
- https://vuldb.com/?ctiid.302006 [REPORT]