Bug 2361317
| Summary: | CVE-2025-32434 python-torchdiffeq: PyTorch: `torch.load` with `weights_only=True` leads to remote code execution [fedora-42] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Avinash Hanwate <ahanwate> |
| Component: | python-torchdiffeq | Assignee: | Tom.Rix |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | 42 | CC: | lx, Tom.Rix |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["1163b22e-b73c-4c02-b8b4-04fa9b4ef3c2"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2025-12-25 22:34:33 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2360999 | ||
|
Description
Avinash Hanwate
2025-04-21 03:37:11 UTC
This flaw is, IIUC, in the base pytorch code, so this package is not directly impacted and this bug can likely be CLOSED as NOTABUG. This package is not directly impacted; this CVE should be patched in the main python-torch package. |