{"id":"CVE-2025-30402","details":"A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f","aliases":["GHSA-h952-963h-rv99","PYSEC-2026-1352"],"modified":"2026-08-12T15:13:24.896659Z","published":"2025-07-11T17:39:26.646Z","database_specific":{"cna_assigner":"facebook","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30402.json","unresolved_ranges":[{"extracted_events":[{"fixed":"https://github.com/pytorch/executorch/commit/93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30402.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30402"},{"type":"ADVISORY","url":"https://www.facebook.com/security/advisories/cve-2025-30402"},{"type":"FIX","url":"https://github.com/pytorch/executorch/commit/93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pytorch/executorch","events":[{"introduced":"0"},{"fixed":"93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f"}],"database_specific":{"source":"REFERENCES"}}],"versions":["ciflow/binaries/sdym","ciflow/binaries/all/sdym","v0.2.0-rc1","v0.1.0-rc1","stable-2023-09-19","stable-2023-09-12","stable-2023-08-29","stable-2023-08-15","stable-2023-08-01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30402.json","vanir_signatures_modified":"2026-08-12T15:13:24Z","vanir_signatures":[{"source":"https://github.com/pytorch/executorch/commit/93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f","target":{"file":"runtime/executor/test/method_meta_test.cpp"},"deprecated":false,"digest":{"line_hashes":["171432949322291117355945229711807023953","299373515690774481358020390649686198753","242841760907499211486838602773840731851","144192044550326894550981364353753848815","197323750424308885027233676695684273159","271009571954446729091065907327564175691","205092980954240165401470866130121996509","236143253699083356072700157180954007832","84308271667666657884065257893911687217","106956963467514092166314793085483000939","156301273979640697730149883800685683073","296959515096674546925081728301778331114","75053671515812773143224228816013318036"],"threshold":0.9},"id":"CVE-2025-30402-57eaea5b","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/pytorch/executorch/commit/93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f","target":{"file":"runtime/executor/method_meta.cpp","function":"calculate_nbytes"},"deprecated":false,"digest":{"function_hash":"306326485614068124087942198550972443778","length":215},"id":"CVE-2025-30402-70eb3e96"},{"signature_version":"v1","source":"https://github.com/pytorch/executorch/commit/93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f","target":{"file":"runtime/executor/method_meta.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["255715795262339041444023741372225131475","215070988325198653738653872342825562949","326404110377927407724359535801718920998","108690749180450374035402411366454870014","69040297860641471100044046056439774806","203755115844283264197198191236706510454","131325377426386145205178143156868549337","269565809294523507478263705860811994281"]},"id":"CVE-2025-30402-be68137f","signature_type":"Line"},{"digest":{"line_hashes":["75735287619305501952517109170801128143","288732472251455090662272580593751631380","120404267144202138552995062800958398510","230365774724856528459289054369988833005","44538765674013094656124112471959722256","92617464741885071234438102595035666090","111846693431572105770341085444092972957","182105955921053927043387412203537015527"],"threshold":0.9},"id":"CVE-2025-30402-e7099a8d","signature_type":"Line","signature_version":"v1","source":"https://github.com/pytorch/executorch/commit/93b1a0c15f7eda49b2bc46b5b4c49557b4e9810f","target":{"file":"runtime/executor/method_meta.cpp"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"}]}