Skip to content
PyTorchPYSEC-2024-250

Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.

Medium5.5CVE-2024-31584 · Published Apr 19, 2024 · updated Jun 4, 2025

Source advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
< 2.2.02.2.0

Changes since it was listed

DateChange
Sep 24Severity: Unrated to Medium
Details and references

Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Severity from
NVD
Also known as
BIT-pytorch-2024-31584, CVE-2024-31584

More PyTorch advisories

All PyTorch
DateAdvisory
Apr 172024PyTorch heap buffer overflow vulnerability
CVE-2024-31580High7.5fixed in 2.2.0
Apr 172024Pytorch use-after-free vulnerability
CVE-2024-31583High7.8fixed in 2.2.0
Oct 292024In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
CVE-2024-48063Critical9.8fixed in 2.5.0
Mar 102025PyTorch Tuple Handler is Vulnerable to Memory Corruption through Manipulation of None Argument
CVE-2025-2148Low5.0no fix yet
Mar 102025PyTorch: Manipulation of the argument scale/zero_point leads to improper initialization via Quantized Sigmoid Module
CVE-2025-2149Low2.5no fix yet
Mar 302025PyTorch susceptible to local Denial of Service
CVE-2025-2953Low3.3fixed in 2.7.1-rc1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.