Security Advisory Issued for PyTorch-Nightly on Linux
NVIDIA has issued a security advisory warning users of its open source machine learning library Pytorch-Nightly on Linux systems that they should uninstall it immediately if it was installed between December 25th and December 30th due to a vulnerability in its torchtrition package which could allow attackers to execute arbitrary code or cause a denial of service attack.
Jan. 05, 2023 2:02AM
Generated in 34.8 seconds

A computer screen displaying an alert about a security vulnerability in Pytorch-Nightly on Linux systems
The open source machine learning library PyTorch has issued a security advisory to users of its nightly binaries on Linux systems. The advisory warns that if the binaries were installed between December 25th and December 30th, they should be uninstalled immediately and replaced with the latest nightly version. The issue was discovered by researchers at NVIDIA, who identified a vulnerability in the torchtrition package included in the PyTorch-nightly installation. According to their report, this vulnerability could allow an attacker to execute arbitrary code on the system or cause a denial of service attack. NVIDIA is recommending that all users of PyTorch-nightly on Linux systems uninstall it and torchtriton immediately and replace it with the latest nightly version available from their website. They have also released a patch for affected versions of torchtrition which can be downloaded from their website as well. PyTorch is one of the most popular open source machine learning libraries used by developers around the world. It provides powerful tools for building deep learning models and allows developers to easily integrate them into applications. This security advisory serves as an important reminder that even open source software can contain vulnerabilities which must be addressed quickly in order to protect users’ data and systems from malicious actors. In response to this security advisory, NVIDIA has released detailed instructions for how users can update their installations of PyTorch-nightly on Linux systems safely and securely. They are also offering additional support through their website for any questions or concerns related to this issue.