CVE-2024-48063: Critical severity pytorch vulnerability
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48063?
The severity of CVE-2024-48063 is considered critical due to the potential for remote code execution via deserialization vulnerabilities in PyTorch.
How do I fix CVE-2024-48063?
To mitigate CVE-2024-48063, upgrade PyTorch to a version beyond 2.4.1 or ensure that distributed computing features are secured against unauthorized access.
What software is affected by CVE-2024-48063?
CVE-2024-48063 affects PyTorch versions up to and including 2.4.1, specifically targeting its RemoteModule in distributed computing contexts.
Is CVE-2024-48063 a disputed vulnerability?
Yes, CVE-2024-48063 is disputed by multiple parties who claim that the behavior is intended within the context of PyTorch's distributed computing capabilities.
What are the potential consequences of CVE-2024-48063?
The potential consequences of CVE-2024-48063 include remote code execution, leading to unauthorized control over systems running vulnerable PyTorch versions.