Skip to content

[GHSA-f4hp-rmr7-r7v8] PyTorch is Vulnerable to Memory Consumption through pad_packed_sequence Function - #9773

Open
JacobMenge wants to merge 1 commit into
JacobMenge/advisory-improvement-9773from
JacobMenge-GHSA-f4hp-rmr7-r7v8
Open

JacobMenge wants to merge 1 commit into
JacobMenge/advisory-improvement-9773from
JacobMenge-GHSA-f4hp-rmr7-r7v8

Conversation

@JacobMenge

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • References

Comments
The fix for this issue (commit 494518046816d29099b7d056a74ffa5c244fdcdd,
PR #167521 "Add empty tensor check for _pad_packed_sequence") was merged on
2025-11-11 and closes pytorch/pytorch#149622. The commit is included in the
v2.10.0 release tag but not in v2.9.0 or v2.9.1, so versions 2.7.0 through
2.9.1 are also affected. The affected range should therefore be < 2.10.0 with
2.10.0 as the first patched version.

@github-actions
github-actions Bot changed the base branch from main to JacobMenge/advisory-improvement-9773 September 24, 2026 19:58
@JacobMenge

Copy link
Copy Markdown
Author

Hi! Quick note: I didn't mean to remove the CVSS v3 score. The improvement form only shows CVSS v4, so it got dropped automatically. Please keep the existing v3 score. The only changes I intended are the fixed version (2.10.0) and the added PR link. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Segmentation fault in torch.nn.utils.rnn.pad_packed_sequence and torch.nn.utils.rnn.unpack_sequence

1 participant