PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-65890 Oneflow Inc. CVE debrief

CVE-2025-65890 is a HIGH severity vulnerability in OneFlow v0.9.0, allowing attackers to cause a Denial of Service (DoS) via an invalid GPU device index. The vulnerability has a CVSS score of 7.5 and is classified as CWE-400. The CVE record was published on 2026-01-28T17:16:08.677Z and was last modified on 2026-07-05T02:17:30.730Z. This vulnerability can have significant impacts on systems utilizing OneFlow, particularly in environments where GPU device indexes are not properly validated. Users of OneFlow v0.9.0 should be aware of this vulnerability and take necessary precautions to prevent exploitation.

Vendor
Oneflow Inc.
Product
OneFlow
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-28
Original CVE updated
2026-07-05
Advisory published
2026-01-28
Advisory updated
2026-07-05

Who should care

Users of OneFlow v0.9.0, particularly those in operator, platform, vulnerability-management, and security teams, should be aware of this vulnerability and take necessary precautions to prevent exploitation. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and planning vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

The vulnerability is caused by a device-ID validation flaw in OneFlow v0.9.0, which allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device index. The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. This issue can be particularly problematic in environments where the GPU device index is not properly validated, allowing for potential exploitation. Users should be cautious and ensure that they are using a version of OneFlow that has addressed this vulnerability.

Defensive priority

High priority should be given to patching or mitigating this vulnerability, as it can be exploited to cause a Denial of Service (DoS). Defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented.

Recommended defensive actions

  • Patch OneFlow to the latest version
  • Restrict access to the vulnerable component
  • Monitor for suspicious activity
  • Implement compensating controls
  • Verify inventory for affected systems

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, including its CVSS score and vector. The source item URL provides additional information on the vulnerability. However, the details provided are limited, and further verification is necessary to fully understand the scope and impact of the vulnerability. Defenders should verify the affected scope, severity, and vendor guidance to ensure proper mitigation.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-65890 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-65890

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-65890 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-65890

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.