Improper resource shutdown or release in PyTorch - CVE-2025-3730
Published: May 13, 2025
Vulnerability identifier: #VU109002
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-3730
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists in the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
PyTorch
watsonx Orchestrate Developer Edition
Knowledge Catalog Premium Cartridge
Maximo Application Suite Ai Service
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
watsonx Orchestrate Developer Edition
Knowledge Catalog Premium Cartridge
Maximo Application Suite Ai Service
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
How to mitigate CVE-2025-3730
Install updates from vendor's website.
PyTorch - update to 2.7.0
watsonx Orchestrate Developer Edition - update to 1.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
Knowledge Catalog Premium Cartridge - update to 5.2
Maximo Application Suite Ai Service - update to 9.0.6
watsonx Orchestrate Developer Edition - update to 1.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
Knowledge Catalog Premium Cartridge - update to 5.2
Maximo Application Suite Ai Service - update to 9.0.6
External References
- https://github.com/pytorch/pytorch/issues/150835
- https://github.com/pytorch/pytorch/issues/150835#issue-2979082232
- https://github.com/pytorch/pytorch/pull/150981
- https://github.com/timocafe/tewart-pytorch/commit/46fc5d8e360127361211cb237d5f9eef0223e567
- https://vuldb.com/?ctiid.305076
- https://vuldb.com/?id.305076
- https://vuldb.com/?submit.553645
Related Security Bulletins
- Improper resource shutdown or release in PyTorch
- IBM Maximo Application Suite Ai-Service Component update for PyTorch
- IBM watsonx Orchestrate Developer Edition update for PyTorch
- IBM Watson Speech Services Cartridge update for PyTorch
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge