PyTorchGHSA-887c-mr87-cxwp
PyTorch Improper Resource Shutdown or Release vulnerability
Medium3.3CVE-2025-3730 · Published Apr 16, 2025 · updated Sep 10, 2026
A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 46fc5d8e360127361211cb237d5f9eef0223e567. It is recommended to apply a patch to fix this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| torch PyPI | < 2.8.0 | 2.8.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-404
- Also known as
- BIT-pytorch-2025-3730, CVE-2025-3730, PYSEC-2026-1970
- nvd.nist.gov/vuln/detail/CVE-2025-3730
- github.com/pytorch/pytorch/issues/150835
- github.com/pytorch/pytorch/pull/150981
- github.com/pytorch/pytorch/commit/01f226bfb8f2c343f5c614a6bbf685d91160f3af
- github.com/timocafe/tewart-pytorch/commit/46fc5d8e360127361211cb237d5f9eef0223e567
- github.com/pytorch/pytorch
- vuldb.com/?ctiid.305076
- vuldb.com/?id.305076
- vuldb.com/?submit.553645
More PyTorch advisories
All PyTorch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 182025 | PyTorch: `torch.load` with `weights_only=True` leads to remote code execution | Critical | 2.6.0 |
| Apr 32025 | PyTorch: memory corruption | Low3.3 | No fix yet |
| Apr 22025 | PyTorch: memory corruption | Medium5.5 | No fix yet |
| Mar 312025 | PyTorch is vulnerable to memory corruption through its torch.lstm_cell function | Low5.3 | 2.10.0 |
| Mar 312025 | PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function | Medium5.3 | No fix yet |
| Mar 312025 | PyTorch is vulnerable to memory corruption through its torch.jit.script function | Low5.3 | 2.13.0 |