Skip to content
PyTorchGHSA-f4hp-rmr7-r7v8

PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function

Medium5.3CVE-2025-2998 · Published Mar 31, 2025 · updated Jun 9, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
<= 2.6.0No fix yet
Details and references

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-119
Also known as
BIT-pytorch-2025-2998, CVE-2025-2998, PYSEC-2025-192

More PyTorch advisories

All PyTorch

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.