Beveiligingsadvies

CVE-2026-24747

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-27 21:13:46
Laatst bijgewerkt 2026-07-15 01:17:00
Toegewezen door GitHub_M
CVSS-score 8.8
Status PUBLISHED

Beschrijving

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.