ExecuTorch Heap Buffer Overflow Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- executorch (pypi)
- Affected versions
- <= 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or <= 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0
- Patched version
- ede82493dae6d2d43f8c424e7be4721abe5242be
An early warning has been issued for a critical heap buffer overflow vulnerability in ExecuTorch. This issue affects various versions of ExecuTorch and could potentially lead to code execution.
What happened
An early warning has been issued regarding a critical heap buffer overflow vulnerability in ExecuTorch. This vulnerability, tracked as GHSA-9M39-3MF3-XWCH, affects multiple versions of ExecuTorch and could potentially allow for code execution or other undesirable effects. The vulnerability is present in versions prior to commit ede82493dae6d2d43f8c424e7be4721abe5242be. The issue has been flagged but is not yet confirmed to be exploited in the wild.
The affected components include executorch (pypi) versions <= 0.6.0 or < 0.7.0, org.pytorch:executorch-android (maven) versions < 0.7.0, and github.com/pytorch/executorch (swift) versions < 0.7.0. Users of these components should assess their exposure based on the version ranges provided.
What to do about it
- Upgrade to ExecuTorch commit ede82493dae6d2d43f8c424e7be4721abe5242be or later to mitigate the vulnerability.
- Check your current version of ExecuTorch against the affected version ranges to determine if an upgrade is necessary.
- Monitor the primary sources for updates on the vulnerability and any official fixes that may be released.
- Consider implementing additional security measures to protect against potential exploitation of this vulnerability.
How 0Day would have caught this
executorch is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using executorch (pypi) versions <= 0.6.0 or < 0.7.0, org.pytorch:executorch-android (maven) versions < 0.7.0, or github.com/pytorch/executorch (swift) versions < 0.7.0.
What should I do right now?
Upgrade to ExecuTorch commit ede82493dae6d2d43f8c424e7be4721abe5242be or later. Check your current version against the affected version ranges and monitor primary sources for updates.
Is there an official fix available?
No official fix has been published yet. Monitor the sources for updates on any released patches.