Debian Package Tracker
Register | Log in
Subscribe

pytorch

Choose email to subscribe with

general
  • source: pytorch (main)
  • version: 2.12.1+dfsg-1
  • maintainer: Debian Deep Learning Team (archive) (DMD)
  • uploaders: Mo Zhou [DMD] – Shengqi Chen [DMD]
  • arch: amd64 arm64 ppc64el riscv64 s390x
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.7.1-7
  • o-o-sec: 1.7.1-7+deb11u1
  • oldstable: 1.13.1+dfsg-4
  • stable: 2.6.0+dfsg-7
  • testing: 2.12.1+dfsg-1
  • unstable: 2.12.1+dfsg-1
versioned links
  • 1.7.1-7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.1-7+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.13.1+dfsg-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.6.0+dfsg-7: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.12.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libtorch-dev
  • libtorch-test
  • libtorch2.12
  • python3-torch (1 bugs: 0, 1, 0, 0)
action needed
A new upstream version is available: 2.13.0 high
A new upstream version 2.13.0 is available, you should consider packaging it.
Created: 2026-07-10 Last update: 2026-07-21 20:00
10 security issues in sid high

There are 10 open security issues in sid.

10 important issues:
  • CVE-2025-2148: A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
  • CVE-2025-2149: A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
  • CVE-2025-2953: A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
  • CVE-2025-3000: A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3121: A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3136: A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
  • CVE-2025-4287: A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as 5827d2061dcb4acd05ac5f8e65d8693a481ba0f5. It is recommended to apply a patch to fix this issue.
  • CVE-2026-4538: A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
  • CVE-2025-55554: pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
  • CVE-2025-63396: An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).
Created: 2025-03-11 Last update: 2026-07-14 05:01
10 security issues in forky high

There are 10 open security issues in forky.

10 important issues:
  • CVE-2025-2148: A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
  • CVE-2025-2149: A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
  • CVE-2025-2953: A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
  • CVE-2025-3000: A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3121: A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3136: A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
  • CVE-2025-4287: A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as 5827d2061dcb4acd05ac5f8e65d8693a481ba0f5. It is recommended to apply a patch to fix this issue.
  • CVE-2026-4538: A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
  • CVE-2025-55554: pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
  • CVE-2025-63396: An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).
Created: 2025-08-09 Last update: 2026-07-14 05:01
lintian reports 4 errors and 2 warnings high
Lintian reports 4 errors and 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-06-30 Last update: 2026-06-30 04:48
debian/patches: 1 patch with invalid metadata, 5 patches to forward upstream high

Among the 17 debian patches available in version 2.12.1+dfsg-1 of the package, we noticed the following issues:

  • 1 patch with invalid metadata that ought to be fixed.
  • 5 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-29 10:49
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-07-21 20:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-07-19 Last update: 2026-07-21 19:01
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 2.12.1+dfsg-2, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit e99ebcda096dfe26538b34a6973002e8c519f919
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Sat Jul 18 20:03:46 2026 -0700

    partial revert of the previous commit. Gbp-Dch: Ignore

commit f2ae8538be4e5ba5320091a8bb0cf43d3cc59173
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Thu Jul 16 22:39:10 2026 -0700

    [ROCM] try to fix FTBFS. Gbp-Dch: Ignore

commit f2c8919fe3ca2c40cfacbd54b374df18f1ffc217
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Tue Jul 14 21:43:50 2026 -0700

    Get rid of tensorpipe for cuda/rocm variants as well.

commit 02b0a58065632e17ea48ac32dc186b550113a9c0
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Tue Jul 14 21:42:36 2026 -0700

    Get rid of tensorpipe from build dependencies.

commit d29dbbf6d29a2e789b0a644924d1ff048dbaa60f
Merge: 931aa6b 8619865
Author: Mo Zhou <lumin@debian.org>
Date:   Sat Jul 11 17:07:42 2026 +0000

    Merge branch 'fix-rocm-7.2' into 'master'
    
    Fix FTBFS on rocm 7.2.x
    
    See merge request deeplearning-team/pytorch!15

commit 8619865c1685cfee9dedeba874ed2b898a2b7790
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Sat Jul 11 13:18:20 2026 +0200

    d/changelog: prep the changelog after successful rocm build

commit a7c53e93af0215bbf13c22400569b8d8933114a0
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Sat Jul 11 10:39:20 2026 +0200

    d/rules: filter out RDNA3 (gfx1100, gfx1101, gfx1102) from target list
    
    LLVM 22, clang aborts with 'fatal error: error in backend: Unsupported
    instruction : <MCInst 4399 ...>' while compiling Loss.hip. Dropping
    gfx110x here until an upstream LLVM fix lands.
    
    Gbp-Dch: full

commit 17a361886db123b0db428cd6102c059a6acdea4c
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 17:46:46 2026 +0200

    d/p/2340-c10d-tests-link-gloo-explicitly.patch: fix linking issue on ProcessGroupGlooTest

commit f1d9a2de1ac14f472586a56c980a2c715e2e52b2
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 17:09:24 2026 +0200

    d/rules: fix ABI incompatiblity hipcc passes clang-abi-compat=17

commit 43f8fab5df94293b4d721ca742bfcbc273dd8c57
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 16:16:50 2026 +0200

    d/control.rocm: bump ROCm stack restriction to 7.2

commit 0e2e8e48378f38d401079a880717e91f94215157
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 16:16:20 2026 +0200

    d/control.rocm: add missing amd-smi dependency

commit 65138000cc8a48841362aed6afee99ad14787687
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 15:54:02 2026 +0200

    d/rules: disabling flash/mem-eff attention for rocm as it requires aotriton
    
    And aotriton is not available in debian and not yet vendored in pytorch
    package
    
    Gbp-Dch: full

commit c2a0fea6170da14fa5599f6743e0a6c23b09686f
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 15:30:55 2026 +0200

    d/p/1070-formatting-fmt11-ostreambuf-iterator.patch: fix format_decimal FTBFS

commit c29e1e19aa40420a027ae818b5005b67d081ff85
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 15:12:53 2026 +0200

    d/control.rocm: restrict libfmt-dev to >= 11.1.1 as older versions fail with clang-22

commit 024a2098d68cce30790e07a879afd1c7a5549814
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 14:54:40 2026 +0200

    d/kineto: patch kineto to not raise severity of Wno-dangling-reference
    
    which is unknown for clang and in rocm kineto builds with -Werror
    causing it to FTBFS
    
    Gbp-Dch: full

commit 1b1d8914837f0b515c21b72da6129f2d5dea0270
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Fri Jul 10 14:47:01 2026 +0200

    d/{rules, control.rocm}: bump to llvm-22 as whole rocm stack >=7.2 relies on llvm-22

commit 931aa6b9dfe8e6596c6f523d201200243cc14914
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 23:33:50 2026 -0700

    [ROCm] add amdgcn-tools-21 to dependencies.

commit 53e146d651405e32405bce9f2ce47b74ff8ec5e6
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 22:46:19 2026 -0700

    [ROCm] minor: use llvm-21 device libs.

commit 7c06cd7e2dc60e97e50eb8b00ca6a6de49050594
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 21:53:37 2026 -0700

    [ROCm] Build depend on composable kernel.

commit f92044b507ab2ad36cbf509e8e3242653deeb203
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 21:09:52 2026 -0700

    [ROCm] Require all rocm B-D to be >= 7.1.0, and add rocm-device-libs-22.

commit cf4302becedd5fcca8f4f083898249be8c849031
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 19:11:58 2026 -0700

    [ROCm] Require libamdhip64-dev (>= 7.1.0~).

commit a79e0fba92776598b262e9e6ed763d8de5f31568
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 18:35:52 2026 -0700

    [ROCm] Patch cmake to prevent aotriton download.

commit 9f5a4d8c343f9a7d2870ac60cfa98f80cf0caac4
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 18:22:57 2026 -0700

    Patch embedded kineto to disable ROCPROF and ROCTRACER.

commit b15ec281fde9aeb9761da9e1123bdac5766ad4a7
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 17:19:51 2026 -0700

    trivial: cleanup more mess

commit e06de1414a5b4fa1d13d4aca6b422cc50b1a767c
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 17:10:06 2026 -0700

    trivial: quilt patch refresh

commit 892a5c8c358c2d16ad5731742b7ff558a9a7fcd4
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Wed Jul 8 17:09:59 2026 -0700

    Cleanup patchset after merging the ROCm fix.

commit 658db3f3f64b5cd1d5bb9b2cc1ed116ce68bb5e7
Merge: 06b7e01 947f26a
Author: Mo Zhou <lumin@debian.org>
Date:   Thu Jul 9 00:05:45 2026 +0000

    Merge branch 'fix-rocm-build' into 'master'
    
    fix rocm build
    
    See merge request deeplearning-team/pytorch!13

commit 947f26a0bf3d134402544755665224e0680d695b
Author: Talha Can Havadar <havadartalha@gmail.com>
Date:   Thu Jul 9 00:05:45 2026 +0000

    fix rocm build

commit 06b7e01a37dbe47449249b768e09a22b7ae28088
Author: Mo Zhou <cdluminate@gmail.com>
Date:   Sun Jun 28 18:48:06 2026 -0700

    autopkgtest: remove the train-mnist.sh test case.

commit 250467156eae99e6bdc8257102a0d66d3cd94156
Author: Aron Xu <happyaron.xu@gmail.com>
Date:   Sun Jun 28 20:45:46 2026 +0800

    d/copyright: exclude __pycache__/*.pyc from repacked tarball
Created: 2026-06-28 Last update: 2026-07-19 04:31
26 low-priority security issues in trixie low

There are 26 open security issues in trixie.

26 issues left for the package maintainer to handle:
  • CVE-2025-2148: (needs triaging) A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
  • CVE-2025-2149: (needs triaging) A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
  • CVE-2025-2953: (needs triaging) A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
  • CVE-2025-2998: (needs triaging) A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
  • CVE-2025-2999: (needs triaging) A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3000: (needs triaging) A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3001: (needs triaging) A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3121: (needs triaging) A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3136: (needs triaging) A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3730: (needs triaging) A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 46fc5d8e360127361211cb237d5f9eef0223e567. It is recommended to apply a patch to fix this issue. The security policy of the project warns to use unknown models which might establish malicious effects.
  • CVE-2025-4287: (needs triaging) A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as 5827d2061dcb4acd05ac5f8e65d8693a481ba0f5. It is recommended to apply a patch to fix this issue.
  • CVE-2026-4538: (needs triaging) A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
  • CVE-2025-46148: (needs triaging) In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
  • CVE-2025-46149: (needs triaging) In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
  • CVE-2025-46150: (needs triaging) In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
  • CVE-2025-46152: (needs triaging) In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
  • CVE-2025-46153: (needs triaging) PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
  • CVE-2025-55551: (needs triaging) An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
  • CVE-2025-55552: (needs triaging) pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
  • CVE-2025-55553: (needs triaging) A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
  • CVE-2025-55554: (needs triaging) pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
  • CVE-2025-55557: (needs triaging) A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
  • CVE-2025-55558: (needs triaging) A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
  • CVE-2025-55560: (needs triaging) An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
  • CVE-2025-63396: (needs triaging) An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).
  • CVE-2026-24747: (needs triaging) PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-03-11 Last update: 2026-07-14 05:01
30 low-priority security issues in bookworm low

There are 30 open security issues in bookworm.

27 issues left for the package maintainer to handle:
  • CVE-2025-2148: (needs triaging) A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component Tuple Handler. The manipulation of the argument None leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.
  • CVE-2025-2149: (needs triaging) A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
  • CVE-2025-2953: (needs triaging) A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The security policy of the project warns to use unknown models which might establish malicious effects.
  • CVE-2025-2998: (needs triaging) A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
  • CVE-2025-2999: (needs triaging) A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3000: (needs triaging) A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3001: (needs triaging) A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3121: (needs triaging) A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3136: (needs triaging) A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAllocator.cpp. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
  • CVE-2025-3730: (needs triaging) A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 46fc5d8e360127361211cb237d5f9eef0223e567. It is recommended to apply a patch to fix this issue. The security policy of the project warns to use unknown models which might establish malicious effects.
  • CVE-2025-4287: (needs triaging) A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as 5827d2061dcb4acd05ac5f8e65d8693a481ba0f5. It is recommended to apply a patch to fix this issue.
  • CVE-2026-4538: (needs triaging) A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.
  • CVE-2025-32434: (needs triaging) PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.
  • CVE-2025-46148: (needs triaging) In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
  • CVE-2025-46149: (needs triaging) In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
  • CVE-2025-46150: (needs triaging) In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
  • CVE-2025-46152: (needs triaging) In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.
  • CVE-2025-46153: (needs triaging) PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.
  • CVE-2025-55551: (needs triaging) An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
  • CVE-2025-55552: (needs triaging) pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
  • CVE-2025-55553: (needs triaging) A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
  • CVE-2025-55554: (needs triaging) pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
  • CVE-2025-55557: (needs triaging) A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
  • CVE-2025-55558: (needs triaging) A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a Denial of Service (DoS).
  • CVE-2025-55560: (needs triaging) An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled by Inductor.
  • CVE-2025-63396: (needs triaging) An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (DoS).
  • CVE-2026-24747: (needs triaging) PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

You can find information about how to handle these issues in the security team's documentation.

3 ignored issues:
  • CVE-2024-31580: PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
  • CVE-2024-31583: Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
  • CVE-2024-31584: Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.
Created: 2024-04-18 Last update: 2026-07-14 05:01
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2025-02-21 Last update: 2026-06-28 21:21
testing migrations
  • This package will soon be part of the auto-fmtlib transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-protobuf transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-benchmark transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-07-14] pytorch 2.12.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-28] Accepted pytorch 2.12.1+dfsg-1 (source) into unstable (Aron Xu)
  • [2026-06-05] pytorch 2.12.0+dfsg2-4 MIGRATED to testing (Debian testing watch)
  • [2026-06-01] Accepted pytorch 2.12.0+dfsg2-4 (source) into unstable (Aron Xu)
  • [2026-05-30] Accepted pytorch 2.12.0+dfsg2-3 (source) into unstable (Aron Xu)
  • [2026-05-25] Accepted pytorch 2.12.0+dfsg2-2 (source) into unstable (Aron Xu)
  • [2026-05-18] Accepted pytorch 2.12.0+dfsg2-1 (source) into unstable (Aron Xu)
  • [2026-05-17] Accepted pytorch 2.12.0+dfsg2-1~exp2 (source) into experimental (Aron Xu)
  • [2026-05-17] Accepted pytorch 2.12.0+dfsg2-1~exp1 (source amd64) into experimental (Debian FTP Masters) (signed by: Aron Xu)
  • [2026-01-29] Accepted pytorch 2.9.1+dfsg-1~exp2 (source) into experimental (Mario Limonciello) (signed by: Dylan Aïssi)
  • [2026-01-13] Accepted pytorch 2.9.1+dfsg-1~exp1 (source) into experimental (Aron Xu) (signed by: Shengqi Chen)
  • [2026-01-09] Accepted pytorch 2.9.0+dfsg-1~exp2 (source) into experimental (Shengqi Chen)
  • [2026-01-02] Accepted pytorch 2.9.0+dfsg-1~exp1 (source amd64) into experimental (Debian FTP Masters) (signed by: Shengqi Chen)
  • [2025-12-01] Accepted pytorch 1.7.1-7+deb11u1 (source amd64) into oldoldstable-security (Daniel Leidert)
  • [2025-09-23] pytorch 2.6.0+dfsg-9 MIGRATED to testing (Debian testing watch)
  • [2025-09-18] Accepted pytorch 2.6.0+dfsg-9 (source) into unstable (Shengqi Chen)
  • [2025-08-21] pytorch 2.6.0+dfsg-8 MIGRATED to testing (Debian testing watch)
  • [2025-08-18] Accepted pytorch 2.6.0+dfsg-8 (source) into unstable (Mo Zhou)
  • [2025-04-21] pytorch 2.6.0+dfsg-7 MIGRATED to testing (Debian testing watch)
  • [2025-04-11] Accepted pytorch 2.6.0+dfsg-7 (source) into unstable (Mo Zhou)
  • [2025-03-16] pytorch 2.6.0+dfsg-5 MIGRATED to testing (Debian testing watch)
  • [2025-03-10] Accepted pytorch 2.6.0+dfsg-5 (source) into unstable (Mo Zhou)
  • [2025-03-06] Accepted pytorch 2.6.0+dfsg-4 (source) into unstable (Mo Zhou)
  • [2025-02-27] pytorch 2.6.0+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2025-02-24] Accepted pytorch 2.6.0+dfsg-3 (source) into unstable (Shengqi Chen)
  • [2025-02-21] Accepted pytorch 2.6.0+dfsg-2 (source) into unstable (Shengqi Chen)
  • [2025-02-17] Accepted pytorch 2.6.0+dfsg-1 (source) into unstable (Shengqi Chen)
  • [2025-01-30] Accepted pytorch 2.6.0+dfsg-1~exp1 (source) into experimental (Shengqi Chen)
  • [2025-01-28] Accepted pytorch 2.6.0~rc9+dfsg-1~exp1 (source amd64) into experimental (Debian FTP Masters) (signed by: Shengqi Chen)
  • [2025-01-07] pytorch 2.5.1+dfsg-4 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 15
  • RC: 0
  • I&N: 13
  • M&W: 2
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (4, 2)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.9.1+dfsg-1~exp1ubuntu2
  • patches for 2.9.1+dfsg-1~exp1ubuntu2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing