PT-2025-39423 · Facebook+1 · Pytorch+1

CVE-2025-55560

·

Published

2025-04-17

·

Updated

2025-12-06

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions pytorch version 2.7.0
Description A flaw exists in pytorch that can result in a Denial of Service (DoS). This occurs when a PyTorch model incorporates both torch.Tensor.to sparse() and torch.Tensor.to dense() and is compiled using Inductor. The issue is related to the interaction between sparse and dense tensor conversions during compilation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-67944
AZL-67968
BDU:2025-12837
BIT-PYTORCH-2025-55560
CVE-2025-55560
ECHO-2A9B-9969-0D91
PYSEC-2025-209

Affected Products

Debian
Pytorch