PyTorch <=2.4.1 RemoteModule Deserialization RCE
CVE-2024-48063 Published on October 29, 2024

In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.

NVD


Products Associated with CVE-2024-48063

Want to know whenever a new CVE is published for Linux Foundation Pytorch? stack.watch will email you.

 

Exploit Probability

EPSS
18.49%
Percentile
95.12%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.