CVE-2025-46150: Medium severity PyTorch PyTorch vulnerability
Published Sep 25, 2025
·Updated
In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
Affected Software
4 affected components
PyTorch PyTorch<2.7.0
linuxfoundation Pytorch Python>=2.6.0<2.7.0
Microsoft cbl2 pytorch 2.0.0-9
Microsoft azl3 pytorch 2.2.2-7
Remediation
Patch Available
Event History
Sep 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityAffected Software
Oct 2, 2025
Data Sourced
via Microsoft·01:05 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:05 AM
Affected Software
Updated
via Microsoft·01:05 AM
Affected Software
Updated
via Microsoft·01:05 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-46150?
The severity of CVE-2025-46150 is considered moderate due to inconsistent results in the FractionalMaxPool2d function.
2
How do I fix CVE-2025-46150?
To fix CVE-2025-46150, upgrade PyTorch to version 2.7.0 or later.
3
What is impacted by CVE-2025-46150?
CVE-2025-46150 specifically impacts PyTorch versions prior to 2.7.0 when using the torch.compile feature.
4
What vulnerabilities are related to CVE-2025-46150?
CVE-2025-46150 is related to issues that arise from inconsistent behavior in CUDA operations in PyTorch.
5
Is CVE-2025-46150 exploitable?
CVE-2025-46150 may lead to incorrect outputs, potentially impacting model performance but does not present a direct security exploit.