Skip to content
PyTorchGHSA-5pcm-hx3q-hm94

PyTorch heap buffer overflow vulnerability

High7.5CVE-2024-31580 · Published Apr 17, 2024 · updated Jul 27, 2026

PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

GitHub advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
< 2.2.02.2.0
Details and references

More PyTorch advisories

All PyTorch
Advisory
PyTorch susceptible to local Denial of Service
Low3.3Mar 30, 2025
A vulnerability was found in PyTorch 2.6.0+cu124
Low2.5Mar 10, 2025
PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
Low5.0Mar 10, 2025
PyTorch: unsafe deserialization
Critical9.8Oct 29, 2024
PyTorch: out-of-bounds read
Medium5.5Apr 19, 2024
Pytorch use-after-free vulnerability
High7.8Apr 17, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.