CVE-2025-65890
A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device index.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
http://oneflow.com, https://github.com/Daisy2ang, https://github.com/Oneflow-Inc/oneflow/issues/10662, https://github.com/Oneflow-Inc/oneflow/issues/10662, https://github.com/Oneflow-Inc/oneflow, https://github.com/Oneflow-Inc/oneflow/issues/10662
