PyTorchGHSA-vgrw-7cvw-pwgx
PyTorch is vulnerable to memory corruption through its unpack_sequence function
Medium5.3CVE-2025-2999 · Published Mar 31, 2025 · updated Jun 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| torch PyPI | < 2.9.1 | 2.9.1 |
Details and references
A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. A patch is available through commit [4945180](https://github.com/pytorch/pytorch/commit/494518046816d29099b7d056a74ffa5c244fdcdd).
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-119
- Also known as
- BIT-pytorch-2025-2999, CVE-2025-2999, PYSEC-2025-193
- nvd.nist.gov/vuln/detail/CVE-2025-2999
- github.com/pytorch/pytorch/issues/149622
- github.com/pytorch/pytorch/issues/149622#issue-2935495265
- github.com/pytorch/pytorch/commit/494518046816d29099b7d056a74ffa5c244fdcdd
- github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-193.yaml
- github.com/pytorch/pytorch
- vuldb.com/?ctiid.302048
- vuldb.com/?id.302048
- vuldb.com/?submit.524198