DEBIAN-CVE-2025-2149

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2025-2149
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-2149.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-2149
Upstream
Published
2025-03-10T13:15:36Z
Modified
2025-09-18T05:17:54Z
Summary
[none]
Details

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnqSigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zeropoint leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

References

Affected packages

Debian:11 / pytorch

Package

Name
pytorch
Purl
pkg:deb/debian/pytorch?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / pytorch

Package

Name
pytorch
Purl
pkg:deb/debian/pytorch?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / pytorch

Package

Name
pytorch
Purl
pkg:deb/debian/pytorch?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / pytorch

Package

Name
pytorch
Purl
pkg:deb/debian/pytorch?arch=source

Affected ranges

Ecosystem specific

{
    "urgency": "not yet assigned"
}