Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Jul 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pytorch
Pytorch vision |
|
| Vendors & Products |
Pytorch
Pytorch vision |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents. | |
| Title | PyTorch torchvision GIF Decoder Out-of-bounds Heap Read | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-24T21:35:27.812Z
Reserved: 2026-07-23T12:51:09.596Z
Link: CVE-2026-65918
Updated: 2026-07-23T18:11:56.623Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T12:51:13Z