CVE-2025-46149: Medium severity PyTorch PyTorch vulnerability
Published Sep 25, 2025
·Updated
In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
Affected Software
4 affected components
PyTorch PyTorch<2.7.0
linuxfoundation Pytorch Python>=2.6.0<2.7.0
Microsoft cbl2 pytorch 2.0.0-9
Microsoft azl3 pytorch 2.2.2-7
Remediation
Patch Available
Event History
Sep 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 2, 2025
Data Sourced
via Microsoft·01:05 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:05 AM
Affected Software
Updated
via Microsoft·01:05 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-46149?
CVE-2025-46149 has a severity level classified as medium due to the potential for assertion errors affecting functionality.
2
How do I fix CVE-2025-46149?
To mitigate CVE-2025-46149, upgrade PyTorch to version 2.7.0 or later where the issue has been resolved.
3
What products are affected by CVE-2025-46149?
CVE-2025-46149 affects all versions of PyTorch prior to 2.7.0.
4
What component does CVE-2025-46149 impact within PyTorch?
CVE-2025-46149 specifically impacts the nn.Fold component when using the inductor.
5
Is there a workaround for CVE-2025-46149 if I cannot upgrade?
There is no known effective workaround for CVE-2025-46149 other than upgrading to a secure version.