Buffer overflow in PyTorch - CVE-2025-2148

 

Buffer overflow in PyTorch - CVE-2025-2148

Published: March 17, 2026


Vulnerability identifier: #VU124049
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2148
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. A remote attacker can trick the victim into opening a specially crafted file to manipulate the argument None, leading to memory corruption.


Affected software

PyTorch
Knowledge Catalog Premium Cartridge
IBM Watson Knowledge Catalog in Cloud Pak for Data

How to mitigate CVE-2025-2148

Install updates from vendor's website.

PyTorch - update to 2.7.0
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2

External References

Related Security Bulletins