CVE-2024-31580: Buffer Overflow
PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/varargfunctions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/torchto a version that resolves this vulnerability.Fixed in 2.2.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.0-4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31580?
CVE-2024-31580 is classified as a critical vulnerability due to its potential to cause a Denial of Service (DoS) in affected systems.
How do I fix CVE-2024-31580?
To fix CVE-2024-31580, upgrade to PyTorch version 2.2.0 or later.
What components are affected by CVE-2024-31580?
CVE-2024-31580 affects the /runtime/vararg_functions.cpp component in PyTorch prior to version 2.2.0.
Can CVE-2024-31580 lead to data breaches?
While CVE-2024-31580 primarily poses a risk of Denial of Service, it does not directly lead to data breaches.
Is CVE-2024-31580 present in PyTorch versions after 2.2.0?
No, CVE-2024-31580 is not present in PyTorch versions 2.2.0 and later, as this vulnerability has been addressed.