CVE-2025-3730

CVSS 2.0 Score 1.7 of 10 (low)

Details

Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 404

Summary

CVE-2025-3730 is a recently disclosed vulnerability affecting PyTorch 2.6.0. The issue lies within the torch.nn.functional.ctc_loss function in the file Aten/src/ATen/native/LossCTC.cpp. This vulnerability, classified as problematic, can lead to a denial of service. Exploitation requires local access, and the attack method has been made public. To mitigate this risk, it is strongly advised to apply the patch with the commit ID 46fc5d8e360127361211cb237d5f9eef0223e567.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share