REDHAT-BUG-2433612: High severity pypi/torch vulnerability
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's weightsonly unpickler allows an attacker to craft a malicious checkpoint file (.pth) that, when loaded with torch.load(..., weightsonly=True), can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pytorchto a version that resolves this vulnerability.Fixed in 2.10.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2433612?
The severity of REDHAT-BUG-2433612 is high with a rating of 7.
How do I fix REDHAT-BUG-2433612?
To fix REDHAT-BUG-2433612, update PyTorch to version 2.10.0 or later.
What type of vulnerability is REDHAT-BUG-2433612?
REDHAT-BUG-2433612 is a memory corruption vulnerability stemming from the `weights_only` unpickler in PyTorch.
What impact does REDHAT-BUG-2433612 have on systems?
REDHAT-BUG-2433612 can potentially lead to corrupted memory if a malicious checkpoint file is loaded.
Which software is affected by REDHAT-BUG-2433612?
The affected software for REDHAT-BUG-2433612 is the PyTorch package, specifically versions prior to 2.10.0.