Junglewise Threat Intelligence

CVE-2025-3136: PYSEC-2025-197 - A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.cac

CVE-2025-3136 · Severity: medium · CVSS 4 · Published 2025-04-03

Technologies: torch (PyPI). Vendors: PyPI.

Executive brief

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

Affected products

  • PyPI torch

Related threats