Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

PyTorch is vulnerable to memory corruption through its torch.lstm_cell function

GHSA-qfhq-4f3w-5fph · BIT-pytorch-2025-3001 · CVE-2025-3001 · PYSEC-2025-195

Published · Modified

Description

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

A patch is available through commit 999d94b.

Ready to move

Start Securing

Free, no credit card | First findings in minutes