SB2025051310 - Improper resource shutdown or release in PyTorch
Published: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2025-3730)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists in the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://github.com/pytorch/pytorch/issues/150835
- https://github.com/pytorch/pytorch/issues/150835#issue-2979082232
- https://github.com/pytorch/pytorch/pull/150981
- https://github.com/timocafe/tewart-pytorch/commit/46fc5d8e360127361211cb237d5f9eef0223e567
- https://vuldb.com/?ctiid.305076
- https://vuldb.com/?id.305076
- https://vuldb.com/?submit.553645