CVE-2025-2999: PyTorch torch.nn.utils.rnn.unpack_sequence memory corruption
Published Mar 31, 2025
·Updated
A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpacksequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
PyTorch PyTorch
linuxfoundation Pytorch Python=2.6.0
IBM watsonx.data intelligence<=5.2.0, 5.2.1, 5.3.0, 5.3.1
Event History
Mar 31, 2025
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Apr 27, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2999?
CVE-2025-2999 is rated as critical due to its potential for memory corruption.
2
What component is affected by CVE-2025-2999?
CVE-2025-2999 affects the function torch.nn.utils.rnn.unpack_sequence in PyTorch 2.6.0.
3
Who can exploit CVE-2025-2999?
Exploitation of CVE-2025-2999 requires a local attack.
4
What is the impact of CVE-2025-2999?
The exploitation of CVE-2025-2999 can lead to memory corruption.
5
How do I fix CVE-2025-2999?
To fix CVE-2025-2999, upgrade to the latest version of PyTorch that addresses this vulnerability.