{"id":"CVE-2024-31580","aliases":["BIT-pytorch-2024-31580","GHSA-5pcm-hx3q-hm94","PYSEC-2024-252","PYSEC-2024-328"],"url":"https://o3.security/vulnerability/CVE-2024-31580","summary":"PyTorch heap buffer overflow vulnerability","details":"PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.","published":"2024-04-17T00:00:00Z","modified":"2026-08-12T16:23:51.952940Z","cvss":{"score":4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"torch","fixedVersion":"2.2.0"}],"fix":{"url":"https://github.com/pytorch/pytorch/commit/b5c3a17c2c207ebefcb85043f0cf94be9b2fef81","label":"pytorch/pytorch@b5c3a17"},"references":[{"type":"WEB","url":"https://gist.github.com/1047524396/038c78f2f007345e6f497698ace2aa3d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/31xxx/CVE-2024-31580.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31580"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/commit/b5c3a17c2c207ebefcb85043f0cf94be9b2fef81"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2024-252.yaml"},{"type":"PACKAGE","url":"https://github.com/pytorch/pytorch"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PYTHON-TORCH-6649934"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T16:23:51.952940Z"}}