PyTorchGHSA-c678-jfcj-6jmf
PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
Low5.0CVE-2025-2148 · Published Mar 10, 2025 · updated Jun 9, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| torch PyPI | <= 2.6.0 | No fix yet |
Details and references
A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-119
- Also known as
- BIT-pytorch-2025-2148, CVE-2025-2148, PYSEC-2025-189
- nvd.nist.gov/vuln/detail/CVE-2025-2148
- github.com/pytorch/pytorch/issues/147722
- github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-189.yaml
- github.com/pytorch/pytorch
- github.com/pytorch/pytorch/blob/b0a67c7495bb11ecb23e556058db059ba48354af/torch/autograd/profiler.py#L990
- vuldb.com/?ctiid.299059
- vuldb.com/?id.299059
- vuldb.com/?submit.505959
More PyTorch advisories
All PyTorch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 102025 | PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module CVE-2025-2149Low2.5no fix yet | Low2.5 | No fix yet |
| Mar 302025 | PyTorch susceptible to local Denial of Service CVE-2025-2953Low3.3fixed in 2.7.1-rc1 | Low3.3 | 2.7.1-rc1 |
| Mar 312025 | PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function CVE-2025-2998Medium5.3no fix yet | Medium5.3 | No fix yet |
| Mar 312025 | PyTorch is vulnerable to memory corruption through its torch.jit.script function CVE-2025-3000Low5.3fixed in 2.13.0 | Low5.3 | 2.13.0 |
| Mar 312025 | PyTorch is vulnerable to memory corruption through its unpack_sequence function CVE-2025-2999Medium5.3fixed in 2.9.1 | Medium5.3 | 2.9.1 |
| Mar 312025 | PyTorch is vulnerable to memory corruption through its torch.lstm_cell function CVE-2025-3001Low5.3fixed in 2.10.0 | Low5.3 | 2.10.0 |