CVE-2025-3001: PyTorch torch.lstm_cell memory corruption
Published Mar 31, 2025
·Updated
A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstmcell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Other sources
PyTorch torch.lstmcell memory corruption
— Microsoft
Affected Software
6 affected componentsFixes available
PyTorch PyTorch
linuxfoundation Pytorch Python=2.6.0
Microsoft azl3 pytorch 2.2.2-9
Microsoft cbl2 pytorch 2.0.0-11
Microsoft cbl2 pytorch 2.0.0-12
Microsoft azl3 pytorch 2.2.2-10
Event History
Mar 31, 2025
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Dec 25, 2025
Data Sourced
via Microsoft·01:06 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:06 AM
Affected Software
Updated
via Microsoft·09:06 AM
DescriptionSeverity
Updated
via Microsoft·09:06 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3001?
CVE-2025-3001 is classified as a critical vulnerability.
2
What function is affected by CVE-2025-3001?
CVE-2025-3001 affects the torch.lstm_cell function in PyTorch.
3
What type of vulnerability is CVE-2025-3001?
CVE-2025-3001 is a memory corruption vulnerability.
4
How can CVE-2025-3001 be exploited?
CVE-2025-3001 can be exploited through local manipulation.
5
What version of PyTorch is affected by CVE-2025-3001?
CVE-2025-3001 affects PyTorch version 2.6.0.