<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:31:10.515447+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368279</id>
    <title>EUVD-2026-368279</title>
    <updated>2026-10-06T19:31:10.518069+00:00</updated>
    <content>EUVD-2026-368279</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55093</id>
    <title>fkie_cve-2026-55093</title>
    <updated>2026-10-06T19:31:10.518101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor dimensions, the allocation size, and the reported tensor length. Loading a crafted NNEF archive through model_for_path or model_for_read reaches the default DatLoader and can make the wrapped size check accept a small allocation while data/src/tensor.rs as_slice_unchecked creates a much larger logical slice. Model construction through as_uniform can then read beyond the heap allocation and disclose adjacent data, and later access can terminate the process with a segmentation fault. The affected dense numeric tensor path does not include the independently guarded bool, String, or block-quant paths, and no out-of-bounds write or code execution was demonstrated. This issue is fixed in versions 0.21.16, 0.22.2, and 0.23.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55093"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x5mv-8wgw-29hg</id>
    <title>GHSA-x5mv-8wgw-29hg — tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load</title>
    <updated>2026-10-06T19:31:10.518136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: tract-nnef</p>
<p>- **Component:** `tract-nnef` (`nnef/src/tensors.rs::read_tensor`) + `tract-data` (`data/src/tensor.rs`)
- **Affected versions:** `&lt; 0.21.16`, `0.22.0`–`0.22.2`, `0.23.0`–`0.23.1` — the dense `DatLoader` path was unguarded across all three release lines; patched in 0.21.16 / 0.22.2 / 0.23.1
- **Class:** CWE-190 (integer overflow) → CWE-125 (out-of-bounds read)
- **Trigger:** loading a crafted NNEF model archive (`*.nnef.tgz` / `*.nnef.tar` / dir) via the public `tract_nnef::nnef().model_for_path` / `model_for_read`
- **Impact:** `read_tensor` returns a memory-unsafe tensor (reported `len` 2^61 over a 56-byte heap allocation). Always-on primitive: a **bounded heap out-of-bounds read** during model build (`as_uniform`), an adjacent-heap information-disclosure reachable via the public load API. The resulting slice is an unsound `from_raw_parts(ptr, 2^61)` that **SIGSEGVs (DoS)** on any access past the mapped region (demonstrated by direct access). No out-of-bounds write and no RCE were achieved — tract's const-folding/`as_uniform` fast-paths fold simple consuming graphs without the full read.
- **Severity:** Medium</p>
<p>## Summary</p>
<p>`read_tensor` builds a tensor `shape` from attacker-controlled 32-bit dimensions and computes the element count `len = product(shape)` and the byte allocation `product(shape) * size_of(dt)` with **unchecked `usize` arithmetic**. In `--release` (no `overflow-checks`), both products wrap modulo 2^64. An attacker chooses dimensions so that the wrapped produ…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x5mv-8wgw-29hg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2026-0217</id>
    <title>RUSTSEC-2026-0217 — Integer overflow in tract-nnef NNEF tensor parser leads to out-of-bounds read on model load</title>
    <updated>2026-10-06T19:31:10.518219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: tract-nnef</p>
<p>`tract_nnef::tensors::read_tensor` builds a tensor shape from attacker-controlled
32-bit dimensions and computes both the element count `product(shape)` and the
byte allocation `product(shape) * size_of(dt)` with **unchecked `usize`
arithmetic**. In release builds (no `overflow-checks`) both products wrap modulo
2^64.</p>
<p>A crafted NNEF `.dat` tensor can choose dimensions whose wrapped products
collapse to a small value that satisfies the header size-consistency check, while
the true element count stays astronomically large. `read_tensor` then returns a
`Tensor` whose reported `len` (e.g. `2^61 + 7`) far exceeds its backing heap
allocation (e.g. 56 bytes). The unchecked accessor `as_slice_unchecked`
(`slice::from_raw_parts(ptr, self.len())`) subsequently yields a slice spanning
~18 EiB over the small buffer.</p>
<p>The out-of-bounds read fires automatically during model build (no inference
required), reachable through the default `DatLoader` resource loader via the
public `tract_nnef::nnef().model_for_path` / `model_for_read` API when the
const-folding `as_uniform` fast-path materializes the over-long constant. The
always-on primitive is a bounded adjacent-heap over-read (information
disclosure); access further past the mapped region SIGSEGVs (denial of service).
No out-of-bounds write or code execution was demonstrated.</p>
<p>Affected: every release line prior to the backported fixes — `&lt; 0.21.16`,
`0.22.0`–`0.22.1`, and `0.23.0`. The block-quant path had already received an
analogous bl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2026-0217"/>
  </entry>
</feed>
