ExecuTorch Integer Overflow Vulnerability: Early Warning for Users
- Severity
- HIGH
- Affected component
- executorch (pypi)
- Affected versions
- <= 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or <= 0.6.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0 or < 0.7.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.2, <= 0.1.2 or >= 0.2.0, <= 0.2.0 or >= 0.2.1, <= 0.2.1 or >= 0.3.0, <= 0.3.0 or >= 0.4.0, <= 0.4.0 or >= 0.5.0, <= 0.5.0 or >= 0.6.0, <= 0.6.0
- Patched version
- Not yet available
An integer overflow vulnerability in ExecuTorch may lead to code execution. Users of affected versions should assess their exposure and apply recommended mitigations.
What happened
An integer overflow vulnerability has been reported in ExecuTorch, a software component used for loading models. This vulnerability, tracked as GHSA-HJ95-MHGF-JXC4, can result in overlapping memory allocations, which may allow an attacker to execute arbitrary code or cause other undesirable effects. The issue affects versions prior to commit d158236b1dc84539c1b16843bc74054c9dcba006.
The vulnerability impacts multiple components and version ranges within the ExecuTorch ecosystem. Users are advised to review the affected version ranges and determine if their installations are vulnerable. The primary sources indicate that no exploitation in the wild has been confirmed at this time.
What to do about it
- Upgrade executorch to commit d158236b1dc84539c1b16843bc74054c9dcba006 or later to mitigate the vulnerability.
- Check your installations against the affected version ranges provided in the threat data to determine if an upgrade is necessary.
- Monitor the primary sources for updates on the vulnerability and any additional mitigations that may be released.
How 0Day would have caught this
executorch is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using executorch (pypi) versions <= 0.6.0 or < 0.7.0, org.pytorch:executorch-android (maven) versions < 0.7.0, or github.com/pytorch/executorch (swift) versions < 0.7.0.
What should I do right now?
Upgrade executorch to commit d158236b1dc84539c1b16843bc74054c9dcba006 or later. Check your installations against the affected version ranges and monitor the primary sources for updates.
Is there an official fix available?
Yes, upgrading to commit d158236b1dc84539c1b16843bc74054c9dcba006 or later is recommended to mitigate the vulnerability.