Intel

AIKIDO-2026-10106

tensordict is vulnerable to Race Condition

Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

16

Low Risk

This Affects:

PYTHONtensordict
0.0.1 - 0.10.0
Fixed in 0.11.0

TL;DR

Affected versions of this package perform in-place modification of input tensors in the functional_masked_fill! implementation, which could lead to silent data corruption or unexpected behavior when functions that are intended to be non-destructive modify shared underlying memory. The patched version changes functional_masked_fill! to avoid modifying the original input tensor in place, preventing unintended side effects that could be exploited in complex tensor pipelines.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

tensordict is vulnerable to Race Condition in versions 0.0.1 - 0.10.0.

How to fix this

Upgrade the tensordict library to the patch version.

Background Info