Improper resource shutdown or release in PyTorch - CVE-2025-3730

 

Improper resource shutdown or release in PyTorch - CVE-2025-3730

Published: May 13, 2025


Vulnerability identifier: #VU109002
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-3730
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists in the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

PyTorch
watsonx Orchestrate Developer Edition
Knowledge Catalog Premium Cartridge
Maximo Application Suite Ai Service
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2025-3730

Install updates from vendor's website.

PyTorch - update to 2.7.0
watsonx Orchestrate Developer Edition - update to 1.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
Knowledge Catalog Premium Cartridge - update to 5.2
Maximo Application Suite Ai Service - update to 9.0.6

External References

Related Security Bulletins