PyTorchGHSA-f4hp-rmr7-r7v8
PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
Medium5.3CVE-2025-2998 · Published Mar 31, 2025 · updated Jun 9, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| torch PyPI | <= 2.6.0 | No fix yet |
Details and references
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-119
- Also known as
- BIT-pytorch-2025-2998, CVE-2025-2998, PYSEC-2025-192
- nvd.nist.gov/vuln/detail/CVE-2025-2998
- github.com/pytorch/pytorch/issues/149622
- github.com/pytorch/pytorch/issues/149622#issue-2935495265
- github.com/pytorch/pytorch/commit/494518046816d29099b7d056a74ffa5c244fdcdd
- github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-192.yaml
- github.com/pytorch/pytorch
- vuldb.com/?ctiid.302047
- vuldb.com/?id.302047
- vuldb.com/?submit.524151