Asymmetric denial of service - ReDoS In pytorch
Description
A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | =2.12.0+dfsg2-1 || =2.12.0+dfsg2-1~exp1 || =2.12.0+dfsg2-1~exp2 || =2.12.0+dfsg2-2 || =2.12.0+dfsg2-3 || =2.12.0+dfsg2-4 || =2.6.0+dfsg-7 || =2.6.0+dfsg-8 || =2.6.0+dfsg-9 || =2.9.0+dfsg-1~exp1 || =2.9.0+dfsg-1~exp2 || =2.9.1+dfsg-1~exp1 || =2.9.1+dfsg-1~exp2 | - | |
debian 12 | =1.13.1+dfsg-4 || =1.13.1+dfsg-5 || =2.0.1+dfsg-1 || =2.0.1+dfsg-1~exp1 || =2.0.1+dfsg-2 || =2.0.1+dfsg-4 || =2.0.1+dfsg-5 || =2.1.2+dfsg-1 || =2.1.2+dfsg-2 || =2.1.2+dfsg-4 || =2.12.0+dfsg2-1 || =2.12.0+dfsg2-1~exp1 || =2.12.0+dfsg2-1~exp2 || =2.12.0+dfsg2-2 || =2.12.0+dfsg2-3 || =2.12.0+dfsg2-4 || =2.4.1-1 || =2.4.1-3 || =2.4.1-4 || =2.5.0+dfsg-1 || =2.5.1+dfsg-1 || =2.5.1+dfsg-3 || =2.5.1+dfsg-4 || =2.6.0+dfsg-1 || =2.6.0+dfsg-1~exp1 || =2.6.0+dfsg-2 || =2.6.0+dfsg-3 || =2.6.0+dfsg-4 || =2.6.0+dfsg-5 || =2.6.0+dfsg-7 || =2.6.0+dfsg-8 || =2.6.0+dfsg-9 || =2.6.0~rc9+dfsg-1~exp1 || =2.9.0+dfsg-1~exp1 || =2.9.0+dfsg-1~exp2 || =2.9.1+dfsg-1~exp1 || =2.9.1+dfsg-1~exp2 | - | |
debian 11 | =1.12.0-1 || =1.12.0~rc1-1 || =1.12.1-1 || =1.13.1+dfsg-1 || =1.13.1+dfsg-2 || =1.13.1+dfsg-3 || =1.13.1+dfsg-4 || =1.13.1+dfsg-5 || =1.7.1-7 || =1.7.1-7+deb11u1 || =1.8.1-1 || =1.8.1-2 || =1.8.1-3 || =1.8.1-4 || =1.8.1-5 || =2.0.1+dfsg-1 || =2.0.1+dfsg-1~exp1 || =2.0.1+dfsg-2 || =2.0.1+dfsg-4 || =2.0.1+dfsg-5 || =2.1.2+dfsg-1 || =2.1.2+dfsg-2 || =2.1.2+dfsg-4 || =2.12.0+dfsg2-1 || =2.12.0+dfsg2-1~exp1 || =2.12.0+dfsg2-1~exp2 || =2.12.0+dfsg2-2 || =2.12.0+dfsg2-3 || =2.12.0+dfsg2-4 || =2.4.1-1 || =2.4.1-3 || =2.4.1-4 || =2.5.0+dfsg-1 || =2.5.1+dfsg-1 || =2.5.1+dfsg-3 || =2.5.1+dfsg-4 || =2.6.0+dfsg-1 || =2.6.0+dfsg-1~exp1 || =2.6.0+dfsg-2 || =2.6.0+dfsg-3 || =2.6.0+dfsg-4 || =2.6.0+dfsg-5 || =2.6.0+dfsg-7 || =2.6.0+dfsg-8 || =2.6.0+dfsg-9 || =2.6.0~rc9+dfsg-1~exp1 || =2.9.0+dfsg-1~exp1 || =2.9.0+dfsg-1~exp2 || =2.9.1+dfsg-1~exp1 || =2.9.1+dfsg-1~exp2 | - | |
debian 14 | =2.12.0+dfsg2-1~exp1 || =2.12.0+dfsg2-1~exp2 || =2.6.0+dfsg-7 || =2.6.0+dfsg-8 || =2.6.0+dfsg-9 || =2.9.0+dfsg-1~exp1 || =2.9.0+dfsg-1~exp2 || =2.9.1+dfsg-1~exp1 || =2.9.1+dfsg-1~exp2 || >=0 <2.12.0+dfsg2-1 | 2.12.0+dfsg2-1 | |
pypi | =1.0.0 || =1.0.1 || =1.1.0 || =1.10.0 || =1.10.1 || =1.10.2 || =1.11.0 || =1.12.0 || =1.12.1 || =1.13.0 || =1.13.1 || =1.2.0 || =1.3.0 || =1.3.1 || =1.4.0 || =1.5.0 || =1.5.1 || =1.6.0 || =1.7.0 || =1.7.1 || =1.8.0 || =1.8.1 || =1.9.0 || =1.9.1 || =2.0.0 || =2.0.1 || =2.1.0 || =2.1.1 || =2.1.2 || =2.2.0 || =2.2.1 || =2.2.2 || =2.3.0 || =2.3.1 || =2.4.0 || =2.4.1 || =2.5.0 || =2.5.1 || =2.6.0 || =2.7.0 || >=0 <2.7.1 | 2.7.1 |
Aliases
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.