<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:55:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355148</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355148</link>
      <description>EUVD-2026-355148</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355148</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63632</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63632</link>
      <description>&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63632</guid>
    </item>
    <item>
      <title>GHSA-p893-rvq9-2xf9 — ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p893-rvq9-2xf9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onnx&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Heap-buffer-overflow READ (16 bytes) in `Gemm_7_6::adapt_gemm_7_6()` (`onnx/version_converter/adapters/gemm_7_6.h:41`) when `ConvertVersion()` processes a model with a Gemm node whose input tensors have fewer than 2 dimensions. The adapter accesses `B_shape[1]` without checking rank. On Release builds the OOB read is silent; ASan confirms 16-byte read past a 48-byte allocation.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The Gemm 7→6 downgrade adapter reads input shapes without bounds checking:
```cpp
// gemm_7_6.h:26-42
const auto&amp;amp; A_shape = inputs[0]-&amp;gt;sizes();  // May have &amp;lt; 2 elements
const auto&amp;amp; B_shape = inputs[1]-&amp;gt;sizes();  // May have &amp;lt; 2 elements&lt;/p&gt;
&lt;p&gt;if (node-&amp;gt;hasAttribute(ktransB) &amp;amp;&amp;amp; node-&amp;gt;i(ktransB) == 1) {
    MN.emplace_back(B_shape[0]);   // OOB if B has 0 dims
} else {
    MN.emplace_back(B_shape[1]);   // OOB if B has &amp;lt; 2 dims ← CRASH
}
```&lt;/p&gt;
&lt;p&gt;The PoC has input B with shape `[28]` (1 dimension). `B_shape` has 1 element. Accessing `B_shape[1]` reads 16 bytes past the `std::vector&amp;lt;Dimension&amp;gt;` internal storage into adjacent heap memory.&lt;/p&gt;
&lt;p&gt;The same unchecked pattern applies to `A_shape[0]` and `A_shape[1]` at lines 34 and 36.&lt;/p&gt;
&lt;p&gt;**Entry point:** `onnx.version_converter.convert_version(model, 6)` — different from the `InferShapes` bugs reported in separate advisories. This triggers during opset downgrade (7→6).&lt;/p&gt;
&lt;p&gt;### PoC
```python
import base64
import onnx
from onnx import version_converter&lt;/p&gt;
&lt;p&gt;poc_b64 = &amp;#34;CAM6rwEKUQoBQQoBQgoBQRIBWSIER2VtbSoPCgVhbHBoYRUBAQA+oAEBKg4KBGJldGEVAAAAOqABASoNCgZ0dGZsc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onnx&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Heap-buffer-overflow READ (16 bytes) in `Gemm_7_6::adapt_gemm_7_6()` (`onnx/version_converter/adapters/gemm_7_6.h:41`) when `ConvertVersion()` processes a model with a Gemm node whose input tensors have fewer than 2 dimensions. The adapter accesses `B_shape[1]` without checking rank. On Release builds the OOB read is silent; ASan confirms 16-byte read past a 48-byte allocation.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The Gemm 7→6 downgrade adapter reads input shapes without bounds checking:
```cpp
// gemm_7_6.h:26-42
const auto&amp;amp; A_shape = inputs[0]-&amp;gt;sizes();  // May have &amp;lt; 2 elements
const auto&amp;amp; B_shape = inputs[1]-&amp;gt;sizes();  // May have &amp;lt; 2 elements&lt;/p&gt;
&lt;p&gt;if (node-&amp;gt;hasAttribute(ktransB) &amp;amp;&amp;amp; node-&amp;gt;i(ktransB) == 1) {
    MN.emplace_back(B_shape[0]);   // OOB if B has 0 dims
} else {
    MN.emplace_back(B_shape[1]);   // OOB if B has &amp;lt; 2 dims ← CRASH
}
```&lt;/p&gt;
&lt;p&gt;The PoC has input B with shape `[28]` (1 dimension). `B_shape` has 1 element. Accessing `B_shape[1]` reads 16 bytes past the `std::vector&amp;lt;Dimension&amp;gt;` internal storage into adjacent heap memory.&lt;/p&gt;
&lt;p&gt;The same unchecked pattern applies to `A_shape[0]` and `A_shape[1]` at lines 34 and 36.&lt;/p&gt;
&lt;p&gt;**Entry point:** `onnx.version_converter.convert_version(model, 6)` — different from the `InferShapes` bugs reported in separate advisories. This triggers during opset downgrade (7→6).&lt;/p&gt;
&lt;p&gt;### PoC
```python
import base64
import onnx
from onnx import version_converter&lt;/p&gt;
&lt;p&gt;poc_b64 = &amp;#34;CAM6rwEKUQoBQQoBQgoBQRIBWSIER2VtbSoPCgVhbHBoYRUBAQA+oAEBKg4KBGJldGEVAAAAOqABASoNCgZ0dGZsc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p893-rvq9-2xf9</guid>
    </item>
    <item>
      <title>PYSEC-2026-3587 — ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3587</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onnx&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Heap-buffer-overflow READ (16 bytes) in `Gemm_7_6::adapt_gemm_7_6()` (`onnx/version_converter/adapters/gemm_7_6.h:41`) when `ConvertVersion()` processes a model with a Gemm node whose input tensors have fewer than 2 dimensions. The adapter accesses `B_shape[1]` without checking rank. On Release builds the OOB read is silent; ASan confirms 16-byte read past a 48-byte allocation.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The Gemm 7→6 downgrade adapter reads input shapes without bounds checking:
```cpp
// gemm_7_6.h:26-42
const auto&amp;amp; A_shape = inputs[0]-&amp;gt;sizes();  // May have &amp;lt; 2 elements
const auto&amp;amp; B_shape = inputs[1]-&amp;gt;sizes();  // May have &amp;lt; 2 elements&lt;/p&gt;
&lt;p&gt;if (node-&amp;gt;hasAttribute(ktransB) &amp;amp;&amp;amp; node-&amp;gt;i(ktransB) == 1) {
    MN.emplace_back(B_shape[0]);   // OOB if B has 0 dims
} else {
    MN.emplace_back(B_shape[1]);   // OOB if B has &amp;lt; 2 dims ← CRASH
}
```&lt;/p&gt;
&lt;p&gt;The PoC has input B with shape `[28]` (1 dimension). `B_shape` has 1 element. Accessing `B_shape[1]` reads 16 bytes past the `std::vector&amp;lt;Dimension&amp;gt;` internal storage into adjacent heap memory.&lt;/p&gt;
&lt;p&gt;The same unchecked pattern applies to `A_shape[0]` and `A_shape[1]` at lines 34 and 36.&lt;/p&gt;
&lt;p&gt;**Entry point:** `onnx.version_converter.convert_version(model, 6)` — different from the `InferShapes` bugs reported in separate advisories. This triggers during opset downgrade (7→6).&lt;/p&gt;
&lt;p&gt;### PoC
```python
import base64
import onnx
from onnx import version_converter&lt;/p&gt;
&lt;p&gt;poc_b64 = &amp;#34;CAM6rwEKUQoBQQoBQgoBQRIBWSIER2VtbSoPCgVhbHBoYRUBAQA+oAEBKg4KBGJldGEVAAAAOqABASoNCgZ0dGZsc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onnx&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Heap-buffer-overflow READ (16 bytes) in `Gemm_7_6::adapt_gemm_7_6()` (`onnx/version_converter/adapters/gemm_7_6.h:41`) when `ConvertVersion()` processes a model with a Gemm node whose input tensors have fewer than 2 dimensions. The adapter accesses `B_shape[1]` without checking rank. On Release builds the OOB read is silent; ASan confirms 16-byte read past a 48-byte allocation.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The Gemm 7→6 downgrade adapter reads input shapes without bounds checking:
```cpp
// gemm_7_6.h:26-42
const auto&amp;amp; A_shape = inputs[0]-&amp;gt;sizes();  // May have &amp;lt; 2 elements
const auto&amp;amp; B_shape = inputs[1]-&amp;gt;sizes();  // May have &amp;lt; 2 elements&lt;/p&gt;
&lt;p&gt;if (node-&amp;gt;hasAttribute(ktransB) &amp;amp;&amp;amp; node-&amp;gt;i(ktransB) == 1) {
    MN.emplace_back(B_shape[0]);   // OOB if B has 0 dims
} else {
    MN.emplace_back(B_shape[1]);   // OOB if B has &amp;lt; 2 dims ← CRASH
}
```&lt;/p&gt;
&lt;p&gt;The PoC has input B with shape `[28]` (1 dimension). `B_shape` has 1 element. Accessing `B_shape[1]` reads 16 bytes past the `std::vector&amp;lt;Dimension&amp;gt;` internal storage into adjacent heap memory.&lt;/p&gt;
&lt;p&gt;The same unchecked pattern applies to `A_shape[0]` and `A_shape[1]` at lines 34 and 36.&lt;/p&gt;
&lt;p&gt;**Entry point:** `onnx.version_converter.convert_version(model, 6)` — different from the `InferShapes` bugs reported in separate advisories. This triggers during opset downgrade (7→6).&lt;/p&gt;
&lt;p&gt;### PoC
```python
import base64
import onnx
from onnx import version_converter&lt;/p&gt;
&lt;p&gt;poc_b64 = &amp;#34;CAM6rwEKUQoBQQoBQgoBQRIBWSIER2VtbSoPCgVhbHBoYRUBAQA+oAEBKg4KBGJldGEVAAAAOqABASoNCgZ0dGZsc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3587</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-63632</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63632</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: onnx, Ubuntu:Pro:24.04:LTS: onnx, Ubuntu:26.04:LTS: onnx&lt;/p&gt;
&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: onnx, Ubuntu:Pro:24.04:LTS: onnx, Ubuntu:26.04:LTS: onnx&lt;/p&gt;
&lt;p&gt;Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63632</guid>
    </item>
  </channel>
</rss>
