¡¾Îó²îͨ¸æ¡¿PyTorch Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2025-32434)

Ðû²¼Ê±¼ä 2025-04-24

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

PyTorch Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

CVE ID

CVE-2025-32434

Îó²îÀàÐÍ

ÏÂÁîÖ´ÐÐ

·¢Ã÷ʱ¼ä

2025-04-24

Îó²îÆÀ·Ö

9.3

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


PyTorchÊÇÒ»¸ö¿ªÔ´µÄÉî¶Èѧϰ¿ò¼Ü£¬£¬ £¬£¬£¬£¬ÆÕ±éÓÃÓÚ»úеѧϰºÍÈ˹¤ÖÇÄÜÑо¿¡£¡£¡£¡£¡£¡£ËüÌṩǿʢµÄÕÅÁ¿ÅÌË㹦Ч£¬£¬ £¬£¬£¬£¬Ö§³ÖGPU¼ÓËÙ£¬£¬ £¬£¬£¬£¬²¢ÇÒ»ùÓÚ×Ô¶¯Çóµ¼ÏµÍ³£¨autograd£©£¬£¬ £¬£¬£¬£¬Ê¹µÃÄ£×ÓѵÁ·Ô½·¢¸ßЧ¡£¡£¡£¡£¡£¡£PyTorchÒÔÆä¶¯Ì¬ÅÌËãͼºÍÎÞаÐÔÊܵ½Ñо¿Ö°Ô±ºÍ¿ª·¢ÕßµÄÇàíù£¬£¬ £¬£¬£¬£¬Äܹ»ÇáËɹ¹½¨ºÍѵÁ·Éñ¾­ÍøÂç¡£¡£¡£¡£¡£¡£ËüÖ§³Ö¶àÖÖÉî¶ÈѧϰʹÃü£¬£¬ £¬£¬£¬£¬°üÀ¨ÅÌËã»úÊÓ¾õ¡¢×ÔÈ»ÓïÑÔ´¦Öóͷ£µÈ£¬£¬ £¬£¬£¬£¬ÇÒÓëPythonÉú̬ϵͳ¼æÈÝ£¬£¬ £¬£¬£¬£¬Àû±ãÓëÆäËû¹¤¾ßºÍ¿â¼¯³É¡£¡£¡£¡£¡£¡£


2025Äê4ÔÂ24ÈÕ£¬£¬ £¬£¬£¬£¬bevictorΰµÂ¼¯ÍÅVSRC¼à²âµ½PyTorch¹Ù·½Ðû²¼µÄÇ徲ͨ¸æ£¬£¬ £¬£¬£¬£¬Ö¸³öÔÚPyTorch 2.5.1¼°Ö®Ç°°æ±¾Öб£´æÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐУ¨RCE£©Îó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î±¬·¢ÔÚʹÓÃtorch.loadº¯Êý¼ÓÔØÄ£×Óʱ£¬£¬ £¬£¬£¬£¬ÌØÊâÊÇÔÚ²ÎÊýweights_only=True±»ÉèÖõÄÇéÐÎÏ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐжñÒâ´úÂ룬£¬ £¬£¬£¬£¬´Ó¶øÔ¶³Ì¿ØÖÆÏµÍ³¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄÆÀ·ÖΪ9.3·Ö£¬£¬ £¬£¬£¬£¬Îó²î¼¶±ðΪÑÏÖØ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


PyTorch<=2.5.1


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁ PyTorch °æ±¾ 2.6.0 »ò¸ü¸ß°æ±¾£¬£¬ £¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÔ¶³ÌÏÂÁîÖ´ÐУ¨RCE£©Îó²î¡£¡£¡£¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://github.com/pytorch/pytorch/releases/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¬£¬ £¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬ £¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6
https://nvd.nist.gov/vuln/detail/CVE-2025-32434