Source: onnx
Version: 1.20.0-6
Severity: important
Tags: security upstream
Forwarded: https://github.com/onnx/onnx/issues/8036
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for onnx.

CVE-2026-14647[0]:
| A weakness has been identified in onnx up to 1.21.x. This
| vulnerability affects the function convPoolShapeInference_opset19 of
| the file onnx/defs/nn/old.cc of the component onnxruntime. This
| manipulation causes out-of-bounds read. It is possible to initiate
| the attack remotely. The exploit has been made available to the
| public and could be used for attacks. Patch name:
| a7bf3a0f1d18bb62575236ef6e4944980c40e045. It is recommended to apply
| a patch to fix this issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14647
    https://www.cve.org/CVERecord?id=CVE-2026-14647
[1] https://github.com/onnx/onnx/issues/8036
[2] https://github.com/onnx/onnx/pull/8051
[3] https://github.com/onnx/onnx/commit/a7bf3a0f1d18bb62575236ef6e4944980c40e045

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to