CVE-2025-2998: PyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruption
Published Mar 31, 2025
·Updated
A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.padpackedsequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Other sources
PyTorch torch.nn.utils.rnn.padpackedsequence memory corruption
— Microsoft
Affected Software
5 affected components
PyTorch PyTorch
linuxfoundation Pytorch Python=2.6.0
Microsoft azl3 pytorch 2.2.2-7
Microsoft cbl2 pytorch 2.0.0-9
IBM watsonx.data intelligence<=5.2.0, 5.2.1, 5.3.0, 5.3.1
Event History
Mar 31, 2025
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Nov 15, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:01 AM
Affected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Apr 27, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2998?
CVE-2025-2998 has been declared as critical.
2
What does CVE-2025-2998 affect?
CVE-2025-2998 affects the function torch.nn.utils.rnn.pad_packed_sequence in PyTorch 2.6.0.
3
What is the impact of the CVE-2025-2998 vulnerability?
The impact of CVE-2025-2998 is memory corruption.
4
Is local access required to exploit CVE-2025-2998?
Yes, local access is required to exploit CVE-2025-2998.
5
How can I mitigate CVE-2025-2998?
To mitigate CVE-2025-2998, update to a patched version of PyTorch.