CVE-2025-2148: PyTorch Tuple torch.ops.profiler._call_end_callbacks_on_jit_fut memory corruption
A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler.callendcallbacksonjitfut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2148?
CVE-2025-2148 has been declared as critical.
Which component of PyTorch is affected by CVE-2025-2148?
CVE-2025-2148 affects the function torch.ops.profiler._call_end_callbacks_on_jit_fut in the Tuple Handler component.
What type of vulnerability is CVE-2025-2148?
CVE-2025-2148 is a memory corruption vulnerability caused by the manipulation of the argument None.
What versions of PyTorch are affected by CVE-2025-2148?
CVE-2025-2148 affects PyTorch version 2.6.0 with CUDA 12.4 and later.
How do I mitigate CVE-2025-2148?
To mitigate CVE-2025-2148, it is recommended to upgrade to the latest version of PyTorch that addresses this vulnerability.