QID 377870
Date Published: 2023-01-05
QID 377870: PyTorch (torchtriton) Supply Chain Vulnerability
PyTorch is a machine learning framework based on the Torch library, used for applications such as computer vision and natural language processing, originally developed by Meta AI and now part of the Linux Foundation umbrella.
Affected Versions:
PyTorch-nightly on Linux via pip between December 25, 2022 and December 30, 2022.
QID Detection Logic:
The command to provided by PyTorch is used to check vulnerable torchtriton package.
The vulnerability allows attacker to get system information and read sensitive files.
Solution
Customer are advised to patch to the latest version of PyTorch .
Vendor References
- PyTorch Blog -
pytorch.org/blog/compromised-nightly-dependency/
CVEs related to QID 377870
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PyTorch Blog |
|