CVE-2025-2953

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 30, 2025
Updated: Apr 22, 2025
CWE ID 404

Summary

CVE-2025-2953 is a recently disclosed vulnerability affecting PyTorch 2.6.0 with CUDA 12.4. The issue lies within the torch.mkldnn_max_pool2d function, which, when manipulated, can result in a denial-of-service attack. Although the exploit has been made public, the authenticity of the vulnerability remains uncertain. The security team advises caution against using unverified models due to potential malicious implications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PyTorch

Affected Vendors

  • Pytorch
  • Linux Foundation