Integer overflow in PyTorch - CVE-2025-55552
Published: February 19, 2026
Vulnerability identifier: #VU123066
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55552
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to unexpected behavior when the components torch.rot90 and torch.randn_like are used together. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
PyTorch
watsonx Code Assistant On Prem
Maximo Application Suite Ai Service
watsonx Code Assistant On Prem
Maximo Application Suite Ai Service
How to mitigate CVE-2025-55552
Install updates from vendor's website.
watsonx Code Assistant On Prem - update to 5.3.1
Maximo Application Suite Ai Service - update to 9.1.10
Maximo Application Suite Ai Service - update to 9.1.10