CVE-2025-65890
oneflow
A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device index.
- CVSS
- 7.5
- EPSS
- 0.45% 36.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.29