Bug 2450062 (CVE-2026-4538) - CVE-2026-4538 pytorch: PyTorch: Deserialization vulnerability in pt2 Loading Handler allows local impact
Summary: CVE-2026-4538 pytorch: PyTorch: Deserialization vulnerability in pt2 Loading ...
Keywords:
Status: NEW
Alias: CVE-2026-4538
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-22 05:01 UTC by OSIDB Bzimport
Modified: 2026-03-23 10:43 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-22 05:01:37 UTC
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.


Note You need to log in before you can comment on or make changes to this bug.