<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:31:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368279</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368279</link>
      <description>EUVD-2026-368279</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368279</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55093</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55093</link>
      <description>&lt;p&gt;Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor dimensions, the allocation size, and the reported tensor length. Loading a crafted NNEF archive through model_for_path or model_for_read reaches the default DatLoader and can make the wrapped size check accept a small allocation while data/src/tensor.rs as_slice_unchecked creates a much larger logical slice. Model construction through as_uniform can then read beyond the heap allocation and disclose adjacent data, and later access can terminate the process with a segmentation fault. The affected dense numeric tensor path does not include the independently guarded bool, String, or block-quant paths, and no out-of-bounds write or code execution was demonstrated. This issue is fixed in versions 0.21.16, 0.22.2, and 0.23.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor dimensions, the allocation size, and the reported tensor length. Loading a crafted NNEF archive through model_for_path or model_for_read reaches the default DatLoader and can make the wrapped size check accept a small allocation while data/src/tensor.rs as_slice_unchecked creates a much larger logical slice. Model construction through as_uniform can then read beyond the heap allocation and disclose adjacent data, and later access can terminate the process with a segmentation fault. The affected dense numeric tensor path does not include the independently guarded bool, String, or block-quant paths, and no out-of-bounds write or code execution was demonstrated. This issue is fixed in versions 0.21.16, 0.22.2, and 0.23.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55093</guid>
    </item>
    <item>
      <title>GHSA-x5mv-8wgw-29hg — tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x5mv-8wgw-29hg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: tract-nnef&lt;/p&gt;
&lt;p&gt;- **Component:** `tract-nnef` (`nnef/src/tensors.rs::read_tensor`) + `tract-data` (`data/src/tensor.rs`)
- **Affected versions:** `&amp;lt; 0.21.16`, `0.22.0`–`0.22.2`, `0.23.0`–`0.23.1` — the dense `DatLoader` path was unguarded across all three release lines; patched in 0.21.16 / 0.22.2 / 0.23.1
- **Class:** CWE-190 (integer overflow) → CWE-125 (out-of-bounds read)
- **Trigger:** loading a crafted NNEF model archive (`*.nnef.tgz` / `*.nnef.tar` / dir) via the public `tract_nnef::nnef().model_for_path` / `model_for_read`
- **Impact:** `read_tensor` returns a memory-unsafe tensor (reported `len` 2^61 over a 56-byte heap allocation). Always-on primitive: a **bounded heap out-of-bounds read** during model build (`as_uniform`), an adjacent-heap information-disclosure reachable via the public load API. The resulting slice is an unsound `from_raw_parts(ptr, 2^61)` that **SIGSEGVs (DoS)** on any access past the mapped region (demonstrated by direct access). No out-of-bounds write and no RCE were achieved — tract&amp;#39;s const-folding/`as_uniform` fast-paths fold simple consuming graphs without the full read.
- **Severity:** Medium&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`read_tensor` builds a tensor `shape` from attacker-controlled 32-bit dimensions and computes the element count `len = product(shape)` and the byte allocation `product(shape) * size_of(dt)` with **unchecked `usize` arithmetic**. In `--release` (no `overflow-checks`), both products wrap modulo 2^64. An attacker chooses dimensions so that the wrapped produ…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: tract-nnef&lt;/p&gt;
&lt;p&gt;- **Component:** `tract-nnef` (`nnef/src/tensors.rs::read_tensor`) + `tract-data` (`data/src/tensor.rs`)
- **Affected versions:** `&amp;lt; 0.21.16`, `0.22.0`–`0.22.2`, `0.23.0`–`0.23.1` — the dense `DatLoader` path was unguarded across all three release lines; patched in 0.21.16 / 0.22.2 / 0.23.1
- **Class:** CWE-190 (integer overflow) → CWE-125 (out-of-bounds read)
- **Trigger:** loading a crafted NNEF model archive (`*.nnef.tgz` / `*.nnef.tar` / dir) via the public `tract_nnef::nnef().model_for_path` / `model_for_read`
- **Impact:** `read_tensor` returns a memory-unsafe tensor (reported `len` 2^61 over a 56-byte heap allocation). Always-on primitive: a **bounded heap out-of-bounds read** during model build (`as_uniform`), an adjacent-heap information-disclosure reachable via the public load API. The resulting slice is an unsound `from_raw_parts(ptr, 2^61)` that **SIGSEGVs (DoS)** on any access past the mapped region (demonstrated by direct access). No out-of-bounds write and no RCE were achieved — tract&amp;#39;s const-folding/`as_uniform` fast-paths fold simple consuming graphs without the full read.
- **Severity:** Medium&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`read_tensor` builds a tensor `shape` from attacker-controlled 32-bit dimensions and computes the element count `len = product(shape)` and the byte allocation `product(shape) * size_of(dt)` with **unchecked `usize` arithmetic**. In `--release` (no `overflow-checks`), both products wrap modulo 2^64. An attacker chooses dimensions so that the wrapped produ…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x5mv-8wgw-29hg</guid>
    </item>
    <item>
      <title>RUSTSEC-2026-0217 — Integer overflow in tract-nnef NNEF tensor parser leads to out-of-bounds read on model load</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2026-0217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: tract-nnef&lt;/p&gt;
&lt;p&gt;`tract_nnef::tensors::read_tensor` builds a tensor shape from attacker-controlled
32-bit dimensions and computes both the element count `product(shape)` and the
byte allocation `product(shape) * size_of(dt)` with **unchecked `usize`
arithmetic**. In release builds (no `overflow-checks`) both products wrap modulo
2^64.&lt;/p&gt;
&lt;p&gt;A crafted NNEF `.dat` tensor can choose dimensions whose wrapped products
collapse to a small value that satisfies the header size-consistency check, while
the true element count stays astronomically large. `read_tensor` then returns a
`Tensor` whose reported `len` (e.g. `2^61 + 7`) far exceeds its backing heap
allocation (e.g. 56 bytes). The unchecked accessor `as_slice_unchecked`
(`slice::from_raw_parts(ptr, self.len())`) subsequently yields a slice spanning
~18 EiB over the small buffer.&lt;/p&gt;
&lt;p&gt;The out-of-bounds read fires automatically during model build (no inference
required), reachable through the default `DatLoader` resource loader via the
public `tract_nnef::nnef().model_for_path` / `model_for_read` API when the
const-folding `as_uniform` fast-path materializes the over-long constant. The
always-on primitive is a bounded adjacent-heap over-read (information
disclosure); access further past the mapped region SIGSEGVs (denial of service).
No out-of-bounds write or code execution was demonstrated.&lt;/p&gt;
&lt;p&gt;Affected: every release line prior to the backported fixes — `&amp;lt; 0.21.16`,
`0.22.0`–`0.22.1`, and `0.23.0`. The block-quant path had already received an
analogous bl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: tract-nnef&lt;/p&gt;
&lt;p&gt;`tract_nnef::tensors::read_tensor` builds a tensor shape from attacker-controlled
32-bit dimensions and computes both the element count `product(shape)` and the
byte allocation `product(shape) * size_of(dt)` with **unchecked `usize`
arithmetic**. In release builds (no `overflow-checks`) both products wrap modulo
2^64.&lt;/p&gt;
&lt;p&gt;A crafted NNEF `.dat` tensor can choose dimensions whose wrapped products
collapse to a small value that satisfies the header size-consistency check, while
the true element count stays astronomically large. `read_tensor` then returns a
`Tensor` whose reported `len` (e.g. `2^61 + 7`) far exceeds its backing heap
allocation (e.g. 56 bytes). The unchecked accessor `as_slice_unchecked`
(`slice::from_raw_parts(ptr, self.len())`) subsequently yields a slice spanning
~18 EiB over the small buffer.&lt;/p&gt;
&lt;p&gt;The out-of-bounds read fires automatically during model build (no inference
required), reachable through the default `DatLoader` resource loader via the
public `tract_nnef::nnef().model_for_path` / `model_for_read` API when the
const-folding `as_uniform` fast-path materializes the over-long constant. The
always-on primitive is a bounded adjacent-heap over-read (information
disclosure); access further past the mapped region SIGSEGVs (denial of service).
No out-of-bounds write or code execution was demonstrated.&lt;/p&gt;
&lt;p&gt;Affected: every release line prior to the backported fixes — `&amp;lt; 0.21.16`,
`0.22.0`–`0.22.1`, and `0.23.0`. The block-quant path had already received an
analogous bl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2026-0217</guid>
    </item>
  </channel>
</rss>
