PyTorchGHSA-x3gm-94wq-g975
PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module
Low2.5CVE-2025-2149 · Published Mar 10, 2025 · updated Jun 9, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| torch PyPI | <= 2.6.0 | No fix yet |
Details and references
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-665
- Also known as
- BIT-pytorch-2025-2149, CVE-2025-2149, PYSEC-2025-190
- nvd.nist.gov/vuln/detail/CVE-2025-2149
- github.com/pytorch/pytorch/issues/147818
- github.com/pytorch/pytorch/issues/147818#issue-2877301660
- github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-190.yaml
- github.com/pytorch/pytorch
- vuldb.com/?ctiid.299060
- vuldb.com/?id.299060
- vuldb.com/?submit.506563
More PyTorch advisories
All PyTorch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 102025 | PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument CVE-2025-2148Low5.0no fix yet | Low5.0 | No fix yet |
| Mar 302025 | PyTorch susceptible to local Denial of Service CVE-2025-2953Low3.3fixed in 2.7.1-rc1 | Low3.3 | 2.7.1-rc1 |
| Mar 312025 | PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function CVE-2025-2998Medium5.3no fix yet | Medium5.3 | No fix yet |
| Mar 312025 | PyTorch is vulnerable to memory corruption through its torch.jit.script function CVE-2025-3000Low5.3fixed in 2.13.0 | Low5.3 | 2.13.0 |
| Mar 312025 | PyTorch is vulnerable to memory corruption through its unpack_sequence function CVE-2025-2999Medium5.3fixed in 2.9.1 | Medium5.3 | 2.9.1 |
| Mar 312025 | PyTorch is vulnerable to memory corruption through its torch.lstm_cell function CVE-2025-3001Low5.3fixed in 2.10.0 | Low5.3 | 2.10.0 |