Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46562
HistoryApr 22, 2024 - 6:30 a.m.

Out-Of-Bounds Read

2024-04-2206:30:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
pytorch
out-of-bounds read
flatbufferloader
memory corruption

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Pytorch is vulnerable to an Out-of-bounds Read. The vulnerability is caused due to a missing validation for mobile_ivalue_size_ variable for a value greater than ivalues->size() in function FlatbufferLoader::parseModule within torch/csrc/jit/mobile/flatbuffer_loader.cpp. This introduces potential for memory corruption when parsing the mobile_bytecode Module.

CPENameOperatorVersion
torchle2.1.2
torchle2.1.2

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%