Skip to content
PyTorchGHSA-qfhq-4f3w-5fph

PyTorch is vulnerable to memory corruption through its torch.lstm_cell function

Low5.3CVE-2025-3001 · Published Mar 31, 2025 · updated Jun 10, 2026

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. A patch is available through commit [999d94b](https://github.com/pytorch/pytorch/commit/999d94b5ede5f4ec111ba7dd144129e2c2725b03).

GitHub advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
< 2.10.02.10.0
Details and references

More PyTorch advisories

All PyTorch
Advisory
PyTorch: memory corruption
Low3.3Apr 3, 2025
PyTorch: memory corruption
Medium5.5Apr 2, 2025
PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
Medium5.3Mar 31, 2025
PyTorch is vulnerable to memory corruption through its torch.jit.script function
Low5.3Mar 31, 2025
PyTorch is vulnerable to memory corruption through its unpack_sequence function
Medium5.3Mar 31, 2025
PyTorch susceptible to local Denial of Service
Low3.3Mar 30, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.