GHSA-33r8-vrx9-rmcv

Suggest an improvement
Source
https://github.com/advisories/GHSA-33r8-vrx9-rmcv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-33r8-vrx9-rmcv/GHSA-33r8-vrx9-rmcv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-33r8-vrx9-rmcv
Aliases
Published
2025-08-08T00:30:26Z
Modified
2025-08-08T17:57:20.066551Z
Severity
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
ExecuTorch integer overflow vulnerability leads to code execution
Details

An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 8f062d3f661e20bb19b24b767b9a9a46e8359f2b.

Database specific
{
    "nvd_published_at": "2025-08-08T00:15:26Z",
    "github_reviewed": true,
    "github_reviewed_at": "2025-08-08T17:00:01Z",
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-680"
    ]
}
References

Affected packages

PyPI / executorch

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.6.0

Affected versions

0.*

0.1.0
0.1.2
0.2.0
0.2.1
0.3.0
0.4.0
0.5.0
0.6.0