Skip to content

Fix lightning fixed version (2.6.6) and add pytorch-lightning to GHSA-qqmf-gpg7-g8gw - #9660

Merged
advisory-database[bot] merged 1 commit into
github:drago-balto/advisory-improvement-9660from
drago-balto:drago-balto-GHSA-qqmf-gpg7-g8gw
Sep 24, 2026
Merged

advisory-database[bot] merged 1 commit into
github:drago-balto/advisory-improvement-9660from
drago-balto:drago-balto-GHSA-qqmf-gpg7-g8gw

Conversation

@drago-balto

Copy link
Copy Markdown

Summary

This corrects the fixed-version data in GHSA-qqmf-gpg7-g8gw (CVE-2026-58659, PyTorch Lightning checkpoint RCE).

The advisory currently records the lightning fix as 2022.6.15. No such release of the modern lightning package exists; that string is a date-style version from the legacy pytorch-lightning versioning era and sorts as newer than every real 2.x release. As a result, every actually-fixed version (2.6.6 and up) is still reported as vulnerable, and there is no installable version a consumer can upgrade to that satisfies the range.

Changes

  1. lightning: correct the fixed version from 2022.6.15 to 2.6.6.
  2. Add pytorch-lightning (PyPI) as an affected package, fixed in 2.6.6. Both distributions ship the same vulnerable pytorch_lightning code (_load_state / LightningModule.load_from_checkpoint) and are fixed by the same change.

Supporting public references

The fix commit was cherry-picked to the release branch, so it is not a linear git ancestor of the 2.6.6 tag; the version-based fixed value (2.6.6) is the authoritative one and matches the PYSEC records cross-referenced from this advisory.

Change follows the OSV schema and touches only this one advisory.

Copilot AI balanced review requested due to automatic review settings September 21, 2026 20:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The updated ranges are schema-consistent and align with the advisory’s stated first fixed release.

Review effort: Balanced
Findings: None

What changed in this PR

Corrects affected-version metadata for the PyTorch Lightning checkpoint RCE.

Changes:

  • Sets lightning fixed version to 2.6.6.
  • Adds pytorch-lightning as affected through 2.6.5.
File Description
advisories/​github-reviewed/​2026/​07/​GHSA-qqmf-gpg7-g8gw/​GHSA-qqmf-gpg7-g8gw.json Corrects and expands affected package ranges.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions
github-actions Bot changed the base branch from main to drago-balto/advisory-improvement-9660 September 21, 2026 20:22
@yilinzhang130

Copy link
Copy Markdown

Independent confirmation from released artifacts (not advisory metadata), in case it helps this get merged — the main objection to correcting a fixed value is usually "how do we know 2.6.6 actually contains the change", and git ancestry cannot answer it here because the fix was cherry-picked.

Grep the shipped wheels for the allowlist the fix introduces:

u=$(curl -s https://pypi.org/pypi/lightning/2.6.6/json | jq -r '.urls[]|select(.packagetype=="bdist_wheel").url')
curl -sL -o li.whl "$u"; unzip -p li.whl lightning/pytorch/core/saving.py | grep -c _ALLOWED_INSTANTIATORS
wheel core/saving.py hits for _ALLOWED_INSTANTIATORS
lightning-2.6.5-py3-none-any.whl (lightning/pytorch/core/saving.py) 0
lightning-2.6.6-py3-none-any.whl (lightning/pytorch/core/saving.py) 3
pytorch_lightning-2.6.5-py3-none-any.whl (pytorch_lightning/core/saving.py) 0
pytorch_lightning-2.6.6-py3-none-any.whl (pytorch_lightning/core/saving.py) 3

Same git-ancestry trap as described above: compare/2.6.6...d710d68 reports status: diverged (ahead_by 70, behind_by 5), so an ancestor check wrongly concludes that 2.6.6 is unfixed. The wheel contents above are the reproducible check.

Two more points that support the change:

  • Upstream's own changelog, as shipped inside lightning-2.6.6-py3-none-any.whl (lightning/pytorch/CHANGELOG.md), states it under ## [2.6.6] - 2026-09-10 → "Fixed arbitrary code execution in load_from_checkpoint by restricting the _instantiator hyperparameter to an allowlist of trusted instantiators ([#21832])". So 2.6.6 is the first fixed release for both distributions, which also backs change (2) of this PR — pytorch-lightning really is affected and missing from the record.
  • Real impact of the current data: a consumer that upgraded to lightning==2.6.6 today still gets flagged, because fixed: 2022.6.15 sorts above every 2.6.x under PyPI ordering, leaving no satisfying installable version at all. OSV's query API is affected the same way (lightning 2.6.6 → this GHSA only; the PYSEC side correctly reports 2.6.6 as fixed).

+1 on this PR as-is.

@advisory-database
advisory-database Bot merged commit db09a8e into github:drago-balto/advisory-improvement-9660 Sep 24, 2026
1 check passed
@advisory-database

Copy link
Copy Markdown
Contributor

Hi @drago-balto! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants