CVE-2025-2149

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Mar 10, 2025
CWE ID 770

Summary

CVE-2025-2149 is a newly identified vulnerability affecting PyTorch 2.6.0+cu124. This issue lies within the Quantized Sigmoid Module's nnq_Sigmoid function and is considered problematic. Manipulation of the scale/zero_point argument results in improper initialization. Attacks require local access, making exploitation a challenging task. Despite public disclosure, the complexity and difficulty of successfully exploiting this vulnerability are yet to be determined.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share