An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit d158236b1dc84539c1b16843bc74054c9dcba006.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| executorch(PyPI) | 0 | 0.7.0 | N/A |
| org.pytorch:executorch-android(Maven) | 0 | 0.7.0 | N/A |
| executorch(SwiftURL) | 0 | 0.7.0 | N/A |
CVSS Metrics