CVE-2025-54952 Details
Description
An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 8f062d3f661e20bb19b24b767b9a9a46e8359f2b.
A vulnerability allowing integer overflow in the loading of ExecuTorch models has been identified. This overflow can cause memory regions to be allocated in smaller sizes than expected, which may lead to code execution or other negative effects. The issue affects ExecuTorch versions prior to commit 8f062d3f661e20bb19b24b767b9a9a46e8359f2b.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 8, 2025CISA-ADP
Assessed Aug 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pytorch/executorch/commit/8f062d3f661e20bb19b24b767b9a9a46e8359f2b | [email protected] | Source CodeVendor |
| https://www.facebook.com/security/advisories/cve-2025-54952 | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-680 | Integer Overflow to Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| PyTorch ExecuTorch | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 8, 2025 | CVE Modified | CISA-ADP |
| Aug 8, 2025 | CVE Modified | CISA-ADP |
| Aug 8, 2025 | New CVE Received | [email protected] |
Volerion