PT-2026-64043 · Pytorch · Torchvision
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PyTorch torchvision versions prior to 0.28.1
Description
An out-of-bounds heap read occurs in the GIF decoder's
read from tensor() callback because an unclamped length is passed to memcpy. This allows attackers to use malicious or truncated GIF files to trigger a segmentation fault, leading to a denial of service, or to disclose the contents of adjacent heap memory.Recommendations
Update PyTorch torchvision to version 0.28.1 or later.
Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Torchvision