CVE-2025-2998

EUVD-2025-8748
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 9.62%
Affected Products (NVD)
VendorProductVersion
linuxfoundationpytorch
2.6.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pytorch
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
2.12.1+dfsg-1
fixed
sid
2.12.1+dfsg-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pytorch
focal
dne
jammy
needs-triage
noble
dne
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage