CVE-2024-31584: Medium severity PyTorch PyTorch vulnerability
Published Apr 19, 2024
·Updated
Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbufferloader.cpp.
Affected Software
4 affected componentsFixes available
PyTorch PyTorch<2.2.0
linuxfoundation Pytorch Python<2.2.0
Microsoft cbl2 pytorch 2.0.0-8<2.0.0-5
2.0.0-5
Microsoft cbl2 pytorch 2.0.0-5<2.0.0-5
2.0.0-5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.0.0-5
Event History
Apr 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 27, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Updated
via Microsoft·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-31584?
CVE-2024-31584 is classified as a medium severity vulnerability due to its potential to cause out-of-bounds read issues.
2
How do I fix CVE-2024-31584?
To fix CVE-2024-31584, upgrade Pytorch to version 2.2.0 or later.
3
What software is affected by CVE-2024-31584?
CVE-2024-31584 affects Pytorch versions prior to 2.2.0.
4
What are the potential impacts of CVE-2024-31584?
The potential impacts of CVE-2024-31584 include unauthorized access to memory and potential information leakage.
5
How was CVE-2024-31584 discovered?
CVE-2024-31584 was identified during routine code reviews and testing of the Pytorch library.