Skip to content
PyTorchGHSA-3749-ghw9-m3mg

PyTorch susceptible to local Denial of Service

Low3.3CVE-2025-2953 · Published Mar 30, 2025 · updated Sep 10, 2026

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

GitHub advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
< 2.7.1-rc12.7.1-rc1
Details and references

More PyTorch advisories

All PyTorch
Advisory
PyTorch: memory corruption
Low3.3Apr 3, 2025
PyTorch: memory corruption
Medium5.5Apr 2, 2025
PyTorch is vulnerable to memory corruption through its torch.lstm_cell function
Low5.3Mar 31, 2025
PyTorch is vulnerable to memory corruption through its unpack_sequence function
Medium5.3Mar 31, 2025
PyTorch is vulnerable to memory corruption through its torch.jit.script function
Low5.3Mar 31, 2025
PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
Medium5.3Mar 31, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.