Skip to content
PyTorchGHSA-x3gm-94wq-g975

PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module

Low2.5CVE-2025-2149 · Published Mar 10, 2025 · updated Jun 9, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
<= 2.6.0No fix yet
Details and references

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-665
Also known as
BIT-pytorch-2025-2149, CVE-2025-2149, PYSEC-2025-190

More PyTorch advisories

All PyTorch
DateAdvisory
Mar 102025PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
CVE-2025-2148Low5.0no fix yet
Mar 302025PyTorch susceptible to local Denial of Service
CVE-2025-2953Low3.3fixed in 2.7.1-rc1
Mar 312025PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function
CVE-2025-2998Medium5.3no fix yet
Mar 312025PyTorch is vulnerable to memory corruption through its torch.jit.script function
CVE-2025-3000Low5.3fixed in 2.13.0
Mar 312025PyTorch is vulnerable to memory corruption through its unpack_sequence function
CVE-2025-2999Medium5.3fixed in 2.9.1
Mar 312025PyTorch is vulnerable to memory corruption through its torch.lstm_cell function
CVE-2025-3001Low5.3fixed in 2.10.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.