Junglewise Threat Intelligence

CVE-2025-54951: ExecuTorch heap-based buffer overflow in model loading

CVE-2025-54951 · Severity: critical · CVSS 9.8 · Published 2025-08-08

Technologies: executorch (PyPI), github.com/pytorch/executorch (Swift), org.pytorch:executorch-android (Maven). Vendors: PyPI, Swift, PyTorch, Maven.

Executive brief

ExecuTorch is a runtime framework used to execute machine learning models on edge devices and servers. A heap buffer overflow vulnerability in the model loading mechanism can cause crashes and potentially allow remote attackers to execute arbitrary code without authentication or user interaction. This poses a significant risk to applications that load untrusted or attacker-controlled models.

Technical details

ExecuTorch contains heap-based buffer overflow vulnerabilities (CWE-122) in the model loading and tensor parsing components, specifically related to validation of tensor dimension limits. The vulnerability is triggered when malformed or oversized model files are loaded, allowing an attacker to overflow heap-allocated buffers without requiring authentication or user interaction. The attack vector is network-based with low complexity, as an attacker can craft a malicious model file and cause a remote ExecuTorch instance to load it. Successful exploitation can result in denial of service (runtime crash) or arbitrary code execution. The issue was fixed in commit cea9b23aa8ff78aff92829a466da97461cc7930c by validating the kTensorDimensionLimit during model parsing, and patches are available in version 0.7.0 across pip, Maven, and Swift package ecosystems.

Affected products

  • Meta Platforms ExecuTorch < 0.7.0
  • PyTorch executorch (pip) < 0.7.0
  • PyTorch executorch-android (Maven) < 0.7.0
  • PyTorch executorch (Swift) < 0.7.0

Timeline

  • 2025-08-07: disclosed: CVE published by NVD
  • 2025-08-08: disclosed: GHSA advisory published
  • 2025-08-07: patched: Fix committed to repository (cea9b23aa8ff78aff92829a466da97461cc7930c) with version 0.7.0 release

References

Related threats