<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:56:01.283800+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355148</id>
    <title>EUVD-2026-355148</title>
    <updated>2026-10-06T09:56:01.287126+00:00</updated>
    <content>EUVD-2026-355148</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355148"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63632</id>
    <title>fkie_cve-2026-63632</title>
    <updated>2026-10-06T09:56:01.287164+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63632"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p893-rvq9-2xf9</id>
    <title>GHSA-p893-rvq9-2xf9 — ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape</title>
    <updated>2026-10-06T09:56:01.287210+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: onnx</p>
<p>### Summary</p>
<p>Heap-buffer-overflow READ (16 bytes) in `Gemm_7_6::adapt_gemm_7_6()` (`onnx/version_converter/adapters/gemm_7_6.h:41`) when `ConvertVersion()` processes a model with a Gemm node whose input tensors have fewer than 2 dimensions. The adapter accesses `B_shape[1]` without checking rank. On Release builds the OOB read is silent; ASan confirms 16-byte read past a 48-byte allocation.</p>
<p>### Details</p>
<p>The Gemm 7→6 downgrade adapter reads input shapes without bounds checking:
```cpp
// gemm_7_6.h:26-42
const auto&amp; A_shape = inputs[0]-&gt;sizes();  // May have &lt; 2 elements
const auto&amp; B_shape = inputs[1]-&gt;sizes();  // May have &lt; 2 elements</p>
<p>if (node-&gt;hasAttribute(ktransB) &amp;&amp; node-&gt;i(ktransB) == 1) {
    MN.emplace_back(B_shape[0]);   // OOB if B has 0 dims
} else {
    MN.emplace_back(B_shape[1]);   // OOB if B has &lt; 2 dims ← CRASH
}
```</p>
<p>The PoC has input B with shape `[28]` (1 dimension). `B_shape` has 1 element. Accessing `B_shape[1]` reads 16 bytes past the `std::vector&lt;Dimension&gt;` internal storage into adjacent heap memory.</p>
<p>The same unchecked pattern applies to `A_shape[0]` and `A_shape[1]` at lines 34 and 36.</p>
<p>**Entry point:** `onnx.version_converter.convert_version(model, 6)` — different from the `InferShapes` bugs reported in separate advisories. This triggers during opset downgrade (7→6).</p>
<p>### PoC
```python
import base64
import onnx
from onnx import version_converter</p>
<p>poc_b64 = "CAM6rwEKUQoBQQoBQgoBQRIBWSIER2VtbSoPCgVhbHBoYRUBAQA+oAEBKg4KBGJldGEVAAAAOqABASoNCgZ0dGZsc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p893-rvq9-2xf9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3587</id>
    <title>PYSEC-2026-3587 — ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape</title>
    <updated>2026-10-06T09:56:01.287287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: onnx</p>
<p>### Summary</p>
<p>Heap-buffer-overflow READ (16 bytes) in `Gemm_7_6::adapt_gemm_7_6()` (`onnx/version_converter/adapters/gemm_7_6.h:41`) when `ConvertVersion()` processes a model with a Gemm node whose input tensors have fewer than 2 dimensions. The adapter accesses `B_shape[1]` without checking rank. On Release builds the OOB read is silent; ASan confirms 16-byte read past a 48-byte allocation.</p>
<p>### Details</p>
<p>The Gemm 7→6 downgrade adapter reads input shapes without bounds checking:
```cpp
// gemm_7_6.h:26-42
const auto&amp; A_shape = inputs[0]-&gt;sizes();  // May have &lt; 2 elements
const auto&amp; B_shape = inputs[1]-&gt;sizes();  // May have &lt; 2 elements</p>
<p>if (node-&gt;hasAttribute(ktransB) &amp;&amp; node-&gt;i(ktransB) == 1) {
    MN.emplace_back(B_shape[0]);   // OOB if B has 0 dims
} else {
    MN.emplace_back(B_shape[1]);   // OOB if B has &lt; 2 dims ← CRASH
}
```</p>
<p>The PoC has input B with shape `[28]` (1 dimension). `B_shape` has 1 element. Accessing `B_shape[1]` reads 16 bytes past the `std::vector&lt;Dimension&gt;` internal storage into adjacent heap memory.</p>
<p>The same unchecked pattern applies to `A_shape[0]` and `A_shape[1]` at lines 34 and 36.</p>
<p>**Entry point:** `onnx.version_converter.convert_version(model, 6)` — different from the `InferShapes` bugs reported in separate advisories. This triggers during opset downgrade (7→6).</p>
<p>### PoC
```python
import base64
import onnx
from onnx import version_converter</p>
<p>poc_b64 = "CAM6rwEKUQoBQQoBQgoBQRIBWSIER2VtbSoPCgVhbHBoYRUBAQA+oAEBKg4KBGJldGEVAAAAOqABASoNCgZ0dGZsc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3587"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63632</id>
    <title>UBUNTU-CVE-2026-63632</title>
    <updated>2026-10-06T09:56:01.287333+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: onnx, Ubuntu:Pro:24.04:LTS: onnx, Ubuntu:26.04:LTS: onnx</p>
<p>Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63632"/>
  </entry>
</feed>
