CVE-2025-2149
CVE-2025-2149
Título es
CVE-2025-2149
Lun, 10/03/2025 – 13:15
Tipo
CWE-665
Gravedad v2.0
1.00
Gravedad 2.0 Txt
LOW
Título en
CVE-2025-2149
Descripción en
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
10/03/2025
10/03/2025
Vector CVSS:4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vector CVSS:3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Vector CVSS:2.0
AV:L/AC:H/Au:S/C:N/I:P/A:N
Gravedad 4.0
2.00
Gravedad 4.0 txt
LOW
Gravedad 3.1 (CVSS 3.1 Base Score)
2.50
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
LOW
Referencias
https://github.com/pytorch/pytorch/issues/147818
https://github.com/pytorch/pytorch/issues/147818#issue-2877301660
https://vuldb.com/?ctiid_299060=
https://vuldb.com/?id_299060=
https://vuldb.com/?submit_506563=
https://github.com/pytorch/pytorch/issues/147818
https://github.com/pytorch/pytorch/issues/147818#issue-2877301660
Enviar en el boletín
Off
