High severity7.1NVD Advisory· Published Jul 23, 2026· Updated Aug 21, 2026
CVE-2026-65918
CVE-2026-65918
Description
PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ednvdPatch
- github.com/pytorch/vision/pull/9520nvdIssue TrackingPatch
- github.com/pytorch/vision/issues/9551nvdExploitIssue Tracking
- www.vulncheck.com/advisories/pytorch-torchvision-gif-decoder-out-of-bounds-heap-readnvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.