CVE-2025-55557: High severity PyTorch PyTorch vulnerability
Published Sep 25, 2025
·Updated
A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
Affected Software
2 affected components
PyTorch PyTorch
linuxfoundation Pytorch Python<=2.7.0
Remediation
Patch Available
Event History
Sep 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 2, 2025
Data Sourced
via Microsoft·01:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-55557?
CVE-2025-55557 is classified as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2025-55557?
To mitigate CVE-2025-55557, update to a patched version of PyTorch that resolves the issue with torch.cummin in the Inductor compilation.
3
Which versions of PyTorch are affected by CVE-2025-55557?
CVE-2025-55557 affects PyTorch version 2.7.0.
4
What causes the vulnerability CVE-2025-55557?
The vulnerability occurs due to a Name Error in PyTorch models containing torch.cummin when compiled by Inductor.
5
What impact does CVE-2025-55557 have on systems using PyTorch?
The impact of CVE-2025-55557 can lead to a Denial of Service (DoS), affecting the availability of applications using the vulnerable PyTorch version.