安全公告详情

NS-SA-2025-0250

2025-10-23 19:59:52

简介

important: kernel-modules-sub/pytorch security update

严重级别

important

主题

An update for kernel-modules-sub/pytorch is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

kernel-modules-sub:
pytorch:


Security Fix(es):
kernel-modules-sub: BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25177.(CVE-2024-8805)
kernel-modules-sub: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix slab-use-after-free on hdcp_work [Why] A slab-use-after-free is reported when HDCP is destroyed but the property_validate_dwork queue is still running. [How] Cancel the delayed work when destroying workqueue. (cherry picked from commit 725a04ba5a95e89c89633d4322430cfbca7ce128)(CVE-2025-21968)
kernel-modules-sub: bugfix
pytorch: PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.(CVE-2025-32434)
pytorch: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.04B7.

影响组件

  • kernel-modules-sub
  • pytorch

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["kernel-modules-sub-6.6.25-2.1.zncgsl7.1525.x86_64.rpm"],"source":"kernel-modules-sub-6.6.25-2.1.zncgsl7.1525.src.rpm"},{"binary":["pytorch-devel-2.3.1-6.zncgsl7.x86_64.rpm","pytorch-2.3.1-6.zncgsl7.x86_64.rpm"],"source":"pytorch-2.3.1-6.zncgsl7.src.rpm"}]}]}

CVE

参考