CVE-2025-54950 Details
Description
An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit b6b7a16df5e7852d976d8c34c8a7e9a1b6f7d005.
A vulnerability allowing out-of-bounds access has been identified in ExecuTorch models, prior to commit fb03b6f85596a8f954d97929075335255b6a58d4. This vulnerability can cause the runtime to crash and may lead to code execution or other undesirable effects.
Users should update to the version of ExecuTorch that includes the commit fb03b6f85596a8f954d97929075335255b6a58d4, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2025CISA-ADP
Assessed Aug 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| PyTorch ExecuTorch | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 12, 2025 | CVE Modified | CISA-ADP |
| Aug 8, 2025 | CVE Modified | [email protected] |
| Aug 7, 2025 | New CVE Received | [email protected] |
Volerion