Unrated severityOSV Advisory· Published Jan 28, 2026· Updated Jan 29, 2026
CVE-2025-65890
CVE-2025-65890
Description
A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device index.
Affected products
1- Range: v0.3.0, v0.5.0, v0.5.0b1, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.