A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit cea9b23aa8ff78aff92829a466da97461cc7930c.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54951.json",
"cna_assigner": "facebook",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "https://github.com/pytorch/executorch/commit/cea9b23aa8ff78aff92829a466da97461cc7930c"
}
],
"source": "AFFECTED_FIELD"
}
]
}"2026-05-28T07:08:03Z"
[
{
"source": "https://github.com/pytorch/executorch/commit/cea9b23aa8ff78aff92829a466da97461cc7930c",
"digest": {
"length": 2702.0,
"function_hash": "70657680742118056363861746971916495693"
},
"deprecated": false,
"id": "CVE-2025-54951-2617babe",
"signature_version": "v1",
"target": {
"function": "parseTensor",
"file": "runtime/executor/tensor_parser_portable.cpp"
},
"signature_type": "Function"
},
{
"source": "https://github.com/pytorch/executorch/commit/cea9b23aa8ff78aff92829a466da97461cc7930c",
"digest": {
"threshold": 0.9,
"line_hashes": [
"224928593880561869846070578067810275519",
"240543869336225347340831625198115302181",
"241427249866267962502012502970555237421",
"139849032345911037092933887399244204789",
"8428812563860683456259216216943564300",
"279044381482919635398050535631142093543",
"179151029084254662779707308239915044542"
]
},
"deprecated": false,
"id": "CVE-2025-54951-72f52f1b",
"signature_version": "v1",
"target": {
"file": "runtime/executor/tensor_parser_portable.cpp"
},
"signature_type": "Line"
},
{
"source": "https://github.com/pytorch/executorch/commit/cea9b23aa8ff78aff92829a466da97461cc7930c",
"digest": {
"length": 2070.0,
"function_hash": "89893370676549802340356288978603438175"
},
"deprecated": false,
"id": "CVE-2025-54951-9adba138",
"signature_version": "v1",
"target": {
"function": "parseTensor",
"file": "runtime/executor/tensor_parser_aten.cpp"
},
"signature_type": "Function"
},
{
"source": "https://github.com/pytorch/executorch/commit/cea9b23aa8ff78aff92829a466da97461cc7930c",
"digest": {
"threshold": 0.9,
"line_hashes": [
"125039678390203040802080730225756099814",
"241427249866267962502012502970555237421",
"139849032345911037092933887399244204789",
"146301707898574952508755783112266290740",
"221108239385796983507941345773378766297",
"48665207304957942159833918716386967077"
]
},
"deprecated": false,
"id": "CVE-2025-54951-ed7bbb47",
"signature_version": "v1",
"target": {
"file": "runtime/executor/tensor_parser_aten.cpp"
},
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-54951.json"