CVE-2025-55552: Integer Overflow
Published Sep 25, 2025
·Updated
pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randnlike are used together.
Affected Software
7 affected componentsFixes available
PyTorch PyTorch
linuxfoundation Pytorch Python<=2.8.0
Microsoft azl3 pytorch 2.2.2-7
Microsoft cbl2 pytorch 2.0.0-9
Microsoft azl3 pytorch 2.2.2-9
Microsoft cbl2 pytorch 2.0.0-11
IBM watsonx.data intelligence<=5.2.0, 5.2.1, 5.2.2, 5.3.0
Event History
Sep 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Oct 5, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:01 AM
SeverityAffected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Updated
via Microsoft·01:01 AM
Affected Software
Jun 24, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55552?
CVE-2025-55552 is classified as a medium severity vulnerability due to its unexpected behavior in PyTorch.
2
How do I fix CVE-2025-55552?
To mitigate CVE-2025-55552, it is recommended to update to the latest version of PyTorch where the issue is addressed.
3
What components of PyTorch are affected by CVE-2025-55552?
CVE-2025-55552 affects the torch.rot90 and torch.randn_like components in PyTorch.
4
What kind of unexpected behavior is reported in CVE-2025-55552?
CVE-2025-55552 reports that using torch.rot90 and torch.randn_like together may produce unintended results.
5
Which version of PyTorch is affected by CVE-2025-55552?
CVE-2025-55552 specifically affects PyTorch version 2.8.0.