CVE-2025-55552 Details
Description
pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
A vulnerability exists in PyTorch version 2.8.0, where an unexpected behavior occurs when the functions torch.rot90 and torch.randn_like are used together. This issue can lead to incorrect results, as the output from the compiled model with these functions can be swapped compared to the eager execution mode.
Users can upgrade to the latest version of PyTorch, where this issue has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pytorch/pytorch/issues/147847 | CISA-ADP | Issue Tracking |
| https://gist.github.com/shaoyuyoung/0e7d2a586297ae9c8ed14d8706749efc | [email protected] | Third Party Advisory |
| https://github.com/pytorch/pytorch/issues/147847 | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
| CWE-682 | Incorrect Calculation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation pytorch | <= 2.8.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 3, 2025 | Initial Analysis | [email protected] |
| Sep 29, 2025 | CVE Modified | CISA-ADP |
| Sep 25, 2025 | New CVE Received | [email protected] |