An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit d158236b1dc84539c1b16843bc74054c9dcba006.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-23965 ExecuTorch integer overflow vulnerability
Github GHSA Github GHSA GHSA-hj95-mhgf-jxc4 ExecuTorch integer overflow vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 12 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Meta
Meta executorch
Vendors & Products Meta
Meta executorch

Thu, 07 Aug 2025 23:00:00 +0000

Type Values Removed Values Added
Description An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit d158236b1dc84539c1b16843bc74054c9dcba006.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: facebook

Published:

Updated: 2025-08-12T14:11:13.423Z

Reserved: 2025-03-21T19:52:56.086Z

Link: CVE-2025-30404

cve-icon Vulnrichment

Updated: 2025-08-12T14:11:04.786Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-07T23:15:26.233

Modified: 2025-08-12T15:15:29.227

Link: CVE-2025-30404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-12T07:49:19Z