Use-after-free in PyTorch - CVE-2024-31583

 

Use-after-free in PyTorch - CVE-2024-31583

Published: August 13, 2024


Vulnerability identifier: #VU95800
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31583
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a use-after-free error in torch/csrc/jit/mobile/interpreter.cpp. A local user can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

PyTorch
Python for Scientific Computing
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Application Suite

How to mitigate CVE-2024-31583

Install updates from vendor's website.

PyTorch - update to 2.2.0
Python for Scientific Computing - update to 4.2.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.7
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0
IBM Maximo Application Suite - addressed in versions 8.10.10, 8.11.7

External References

Related Security Bulletins