Skip to content

Commit e7cac04

Browse files
authored
Allowlist torch for PT2.5 arm64 (#4877)
1 parent a34c525 commit e7cac04

File tree

4 files changed

+132
-0
lines changed

4 files changed

+132
-0
lines changed
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"torch": [
3+
{
4+
"description": "PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.",
5+
"vulnerability_id": "CVE-2025-32434",
6+
"name": "CVE-2025-32434",
7+
"package_name": "torch",
8+
"package_details": {
9+
"file_path": "/opt/conda/lib/python3.11/site-packages/torch-2.4.0+cpu.dist-info/METADATA",
10+
"name": "torch",
11+
"package_manager": "PYTHON",
12+
"version": "2.4.0+cpu",
13+
"release": null
14+
},
15+
"remediation": {
16+
"recommendation": {
17+
"text": "None Provided"
18+
}
19+
},
20+
"cvss_v3_score": 9.8,
21+
"cvss_v30_score": 0.0,
22+
"cvss_v31_score": 9.8,
23+
"cvss_v2_score": 0.0,
24+
"cvss_v3_severity": "CRITICAL",
25+
"source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32434",
26+
"source": "NVD",
27+
"severity": "CRITICAL",
28+
"status": "ACTIVE",
29+
"title": "CVE-2025-32434 - torch",
30+
"reason_to_ignore": "N/A"
31+
}
32+
]
33+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"torch": [
3+
{
4+
"description": "PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.",
5+
"vulnerability_id": "CVE-2025-32434",
6+
"name": "CVE-2025-32434",
7+
"package_name": "torch",
8+
"package_details": {
9+
"file_path": "/opt/conda/lib/python3.11/site-packages/torch-2.4.0+cpu.dist-info/METADATA",
10+
"name": "torch",
11+
"package_manager": "PYTHON",
12+
"version": "2.4.0+cpu",
13+
"release": null
14+
},
15+
"remediation": {
16+
"recommendation": {
17+
"text": "None Provided"
18+
}
19+
},
20+
"cvss_v3_score": 9.8,
21+
"cvss_v30_score": 0.0,
22+
"cvss_v31_score": 9.8,
23+
"cvss_v2_score": 0.0,
24+
"cvss_v3_severity": "CRITICAL",
25+
"source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32434",
26+
"source": "NVD",
27+
"severity": "CRITICAL",
28+
"status": "ACTIVE",
29+
"title": "CVE-2025-32434 - torch",
30+
"reason_to_ignore": "N/A"
31+
}
32+
]
33+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"torch": [
3+
{
4+
"description": "PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.",
5+
"vulnerability_id": "CVE-2025-32434",
6+
"name": "CVE-2025-32434",
7+
"package_name": "torch",
8+
"package_details": {
9+
"file_path": "/opt/conda/lib/python3.11/site-packages/torch-2.4.0+cpu.dist-info/METADATA",
10+
"name": "torch",
11+
"package_manager": "PYTHON",
12+
"version": "2.4.0+cpu",
13+
"release": null
14+
},
15+
"remediation": {
16+
"recommendation": {
17+
"text": "None Provided"
18+
}
19+
},
20+
"cvss_v3_score": 9.8,
21+
"cvss_v30_score": 0.0,
22+
"cvss_v31_score": 9.8,
23+
"cvss_v2_score": 0.0,
24+
"cvss_v3_severity": "CRITICAL",
25+
"source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32434",
26+
"source": "NVD",
27+
"severity": "CRITICAL",
28+
"status": "ACTIVE",
29+
"title": "CVE-2025-32434 - torch",
30+
"reason_to_ignore": "N/A"
31+
}
32+
]
33+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"torch": [
3+
{
4+
"description": "PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.",
5+
"vulnerability_id": "CVE-2025-32434",
6+
"name": "CVE-2025-32434",
7+
"package_name": "torch",
8+
"package_details": {
9+
"file_path": "/opt/conda/lib/python3.11/site-packages/torch-2.4.0+cpu.dist-info/METADATA",
10+
"name": "torch",
11+
"package_manager": "PYTHON",
12+
"version": "2.4.0+cpu",
13+
"release": null
14+
},
15+
"remediation": {
16+
"recommendation": {
17+
"text": "None Provided"
18+
}
19+
},
20+
"cvss_v3_score": 9.8,
21+
"cvss_v30_score": 0.0,
22+
"cvss_v31_score": 9.8,
23+
"cvss_v2_score": 0.0,
24+
"cvss_v3_severity": "CRITICAL",
25+
"source_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32434",
26+
"source": "NVD",
27+
"severity": "CRITICAL",
28+
"status": "ACTIVE",
29+
"title": "CVE-2025-32434 - torch",
30+
"reason_to_ignore": "N/A"
31+
}
32+
]
33+
}

0 commit comments

Comments
 (0)