What is CVE-2026-65918?
CVE-2026-65918 is an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback in PyTorch torchvision through version 0.28.0. The issue allows attackers to cause a denial of service via segmentation fault by providing malicious or truncated GIF files. The fix is available in commit 4e05dc2.
Azərbaycanca: CVE-2026-65918, PyTorch torchvision kitabxanasının 0.28.0 sürətinə qədər olan versiyalarında, GIF decoder-in read_from_tensor callback funksiyasında aşkarlanan out-of-bounds heap read zəifliyidir. Bu zəiflik, təcavüzkarlara xüsusi hazırlanmış zərərli GIF faylları vasitəsilə denial of service (segmentation fault) yaratmağa imkan verir. Problemin aradan qaldırılması üçün 4e05dc2 commit-i ilə təmin olunmuş düzəliş tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
What software is affected by CVE-2026-65918?
This vulnerability affects PyTorch torchvision library through version 0.28.0.
What is the impact of exploiting CVE-2026-65918?
An attacker can cause a denial of service (segmentation fault) by providing a maliciously crafted GIF file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.