CVE-2025-3730
CVSS 2.0 Score 1.7 of 10 (low)
Details
Published Apr 16, 2025
Updated: Apr 17, 2025
CWE ID 404
Summary
CVE-2025-3730 is a recently disclosed vulnerability affecting PyTorch 2.6.0. The issue lies within the torch.nn.functional.ctc_loss function in the file Aten/src/ATen/native/LossCTC.cpp. This vulnerability, classified as problematic, can lead to a denial of service. Exploitation requires local access, and the attack method has been made public. To mitigate this risk, it is strongly advised to apply the patch with the commit ID 46fc5d8e360127361211cb237d5f9eef0223e567.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PyTorch
Affected Vendors
- Pytorch