From 8c309b80994650c7e07ec46f9236e9e64a84997c Mon Sep 17 00:00:00 2001 From: TPTBusiness Date: Thu, 2 Apr 2026 23:04:09 +0200 Subject: [PATCH] chore: Document torch CVE-2025-2953 is already fixed MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Add comment explaining torch >=2.8.0 is already safe (CVE fixed in >=2.7.1) - Dependabot alert #33 is false positive due to missing lockfile - No version change needed - current specification is already secure Security Status: - CVE-2025-2953: Fixed in torch >=2.7.1, current spec >=2.8.0 ✓ - Affects: torch.mkldnn_max_pool2d function - Impact: Local DoS via improper resource shutdown - Attack vector: Local (requires local access) Note: Without a lockfile (pip-tools/uv/poetry), Dependabot cannot determine the installed version and raises alerts based on the requirement spec alone. --- rdagent/scenarios/rl/autorl_bench/requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/rdagent/scenarios/rl/autorl_bench/requirements.txt b/rdagent/scenarios/rl/autorl_bench/requirements.txt index 542ba2ff..dbf391d8 100644 --- a/rdagent/scenarios/rl/autorl_bench/requirements.txt +++ b/rdagent/scenarios/rl/autorl_bench/requirements.txt @@ -26,7 +26,8 @@ pydantic>=2.4.0 # Security fix: CVE-2024-3772 (ReDoS via crafted email) # Security: transformers >=4.50.0 fixes CVE-2025-1194 (ReDoS in GPT-NeoX-Japanese tokenizer) # Security: transformers >=4.52.1 fixes CVE-2025-3777 (URL validation bypass via username injection) # Current spec (>=4.53.0) is already safe. Dependabot alerts are false positives due to missing lockfile. -torch>=2.8.0 # Security fix: CVE-2025-32434 (torch.load RCE), CVE-2025-3730 (DoS in ctc_loss) +# Security: torch >=2.7.1 fixes CVE-2025-2953 (DoS in mkldnn_max_pool2d) - current spec >=2.8.0 is safe +torch>=2.8.0 # Security fix: CVE-2025-32434 (torch.load RCE), CVE-2025-3730 (DoS in ctc_loss), CVE-2025-2953 (DoS in mkldnn_max_pool2d) transformers>=4.53.0 # Security fix: CVE-2024-11393 (RCE), CVE-2025-3264/3933/2099/6051/1194/6638 (ReDoS), CVE-2025-3777 (URL validation) huggingface_hub>=0.20.0