Buffer overflow in PyTorch - CVE-2025-2148
Published: March 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. A remote attacker can trick the victim into opening a specially crafted file to manipulate the argument None, leading to memory corruption.
Affected software
Knowledge Catalog Premium Cartridge
IBM Watson Knowledge Catalog in Cloud Pak for Data
How to mitigate CVE-2025-2148
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2