SB2025051247 - Multiple vulnerabilities in IBM Maximo Application Suite Ai-Service
Published: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Buffer overflow (CVE-ID: CVE-2025-3121)
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists in the function torch.jit.jit_module_from_flatbuffer. A local user can trigger the vulnerability to cause memory corruption
2) Buffer overflow (CVE-ID: CVE-2025-3136)
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists in the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. A local user can trigger the vulnerability to cause memory corruption.
Remediation
Install update from vendor's website.