安全公告详情

NS-SA-2026-0105

2026-09-07 18:00:00

简介

important: pytorch/git security update

严重级别

important

主题

An update for pytorch/git is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

pytorch:
git:


Security Fix(es):
pytorch: PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.(CVE-2026-24747)
pytorch: bugfix
git: A line-end handling flaw was found in Git. When writing a config entry, values with a trailing carriage return (CR) are not quoted, resulting in the CR being lost when the config is read later. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read, resulting in the submodule being checked out to an incorrect location.(CVE-2025-48384)
git: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • pytorch
  • git

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["pytorch-devel-2.3.1-7.zncgsl7.x86_64.rpm","pytorch-2.3.1-7.zncgsl7.x86_64.rpm"],"source":"pytorch-2.3.1-7.zncgsl7.src.rpm"},{"binary":["perl-Git-SVN-2.41.0-1.zncgsl7.11.noarch.rpm","perl-Git-2.41.0-1.zncgsl7.11.noarch.rpm","git-svn-2.41.0-1.zncgsl7.11.noarch.rpm","git-gui-2.41.0-1.zncgsl7.11.noarch.rpm","gitweb-2.41.0-1.zncgsl7.11.noarch.rpm","git-credential-libsecret-2.41.0-1.zncgsl7.11.x86_64.rpm","git-instaweb-2.41.0-1.zncgsl7.11.noarch.rpm","git-email-2.41.0-1.zncgsl7.11.noarch.rpm","git-subtree-2.41.0-1.zncgsl7.11.noarch.rpm","git-core-doc-2.41.0-1.zncgsl7.11.noarch.rpm","git-p4-2.41.0-1.zncgsl7.11.noarch.rpm","git-daemon-2.41.0-1.zncgsl7.11.x86_64.rpm","gitk-2.41.0-1.zncgsl7.11.noarch.rpm","git-2.41.0-1.zncgsl7.11.x86_64.rpm","git-core-2.41.0-1.zncgsl7.11.x86_64.rpm","git-all-2.41.0-1.zncgsl7.11.noarch.rpm"],"source":"git-2.41.0-1.zncgsl7.11.src.rpm"}]}]}

CVE

参考