Improper Initialization in PyTorch - CVE-2025-2149

 

Improper Initialization in PyTorch - CVE-2025-2149

Published: March 17, 2026


Vulnerability identifier: #VU124048
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2149
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists in the function nnq_Sigmoid of the component Quantized Sigmoid Module. A local user can run a specially crafted application to execute arbitrary code with escalated privileges on the system.


Affected software

PyTorch
Knowledge Catalog Premium Cartridge
IBM Watson Knowledge Catalog in Cloud Pak for Data

How to mitigate CVE-2025-2149

Install updates from vendor's website.

PyTorch - update to 2.7.0
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2

External References

Related Security Bulletins