Vulnerability Description
PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Pytorch | < 2.2.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/1047524396/038c78f2f007345e6f497698ace2aa3dThird Party Advisory
- https://github.com/pytorch/pytorch/commit/b5c3a17c2c207ebefcb85043f0cf94be9b2fefPatch
- https://gist.github.com/1047524396/038c78f2f007345e6f497698ace2aa3dThird Party Advisory
- https://github.com/pytorch/pytorch/commit/b5c3a17c2c207ebefcb85043f0cf94be9b2fefPatch
FAQ
What is CVE-2024-31580?
CVE-2024-31580 is a vulnerability with a CVSS score of 4.0 (MEDIUM). PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (D...
How severe is CVE-2024-31580?
CVE-2024-31580 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-31580?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Pytorch.