Improper resource shutdown or release in PyTorch - CVE-2025-4287

 

Improper resource shutdown or release in PyTorch - CVE-2025-4287

Published: September 26, 2025


Vulnerability identifier: #VU116146
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4287
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in the function torch.cuda.nccl.reduce() of the file torch/cuda/nccl.py. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

PyTorch
watsonx Orchestrate Developer Edition
Knowledge Catalog Premium Cartridge
Maximo Application Suite Ai Service
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data

How to mitigate CVE-2025-4287

Install updates from vendor's website.

PyTorch - update to 2.7.0
watsonx Orchestrate Developer Edition - update to 1.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.2
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Maximo Application Suite Ai Service - update to 9.1.3

External References

Related Security Bulletins