Improper resource shutdown or release in PyTorch - CVE-2025-4287
Published: September 26, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the function torch.cuda.nccl.reduce() of the file torch/cuda/nccl.py. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
watsonx Orchestrate Developer Edition
Knowledge Catalog Premium Cartridge
Maximo Application Suite Ai Service
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
How to mitigate CVE-2025-4287
watsonx Orchestrate Developer Edition - update to 1.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.2
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Maximo Application Suite Ai Service - update to 9.1.3
External References
- https://github.com/Divigroup-RAP/PYTORCH/commit/5827d2061dcb4acd05ac5f8e65d8693a481ba0f5
- https://github.com/pytorch/pytorch/issues/150836
- https://github.com/pytorch/pytorch/issues/150836#issue-2979097872
- https://github.com/pytorch/pytorch/pull/150923
- https://vuldb.com/?ctiid.307394
- https://vuldb.com/?id.307394
- https://vuldb.com/?submit.553644
Related Security Bulletins
- Improper resource shutdown or release in PyTorch
- IBM Maximo AI Service update for PyTorch
- IBM watsonx Orchestrate Developer Edition update for PyTorch
- IBM Watson Speech Services Cartridge update for PyTorch
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem