VDB

CVE-2025-2149

CVE-2025-2149 PUBLISHED

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

EPSS 0.05% · 16.4th percentile

Risk Scores

EPSS Score
0.05%
16.4th percentile

Affected Products

VendorProductVersions
Bitnamipytorch2.6.0
Bitnamipytorch2.6.0

Timeline

  • Mar 10, 2025 CVE Published
  • Mar 10, 2025 CVE Updated
  • Mar 11, 2025 EPSS Score
  • Mar 18, 2025 Coalition ESS Score
  • Mar 25, 2025 EPSS Score
  • Apr 7, 2025 EPSS Score
  • Apr 21, 2025 EPSS Score
  • May 4, 2025 EPSS Score
  • May 18, 2025 EPSS Score
  • Jun 1, 2025 EPSS Score
  • Jun 14, 2025 EPSS Score
  • Jun 23, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›