Heap-based buffer overflow in PyTorch - CVE-2024-31580

 

Heap-based buffer overflow in PyTorch - CVE-2024-31580

Published: August 13, 2024


Vulnerability identifier: #VU95802
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31580
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in component /runtime/vararg_functions.cpp. A local user can pass specially crafted data to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.


Affected software

PyTorch
Python for Scientific Computing
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Maximo Application Suite

How to mitigate CVE-2024-31580

Install updates from vendor's website.

PyTorch - update to 2.2.0
Python for Scientific Computing - update to 4.2.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.7
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0
IBM Maximo Application Suite - addressed in versions 8.10.10, 8.11.7

External References

Related Security Bulletins