Impact
Tract is a lightweight inference toolkit that parses NNEF of usize dimensions in the dense numeric tensor path; when a malicious NNEF archive supplies oversized dimensions, the multiplication overflows, causing an allocation that is smaller than the logical data slice. During loading via model_for_path or model_for_read, this leads to an out-of-bounds read that can expose adjacent memory and may trigger a segmentation fault. The bool, String, and block-quant tensor paths are independently guarded, and no out-of-bounds write or code execution was demonstrated.
Affected Systems
The flaw affects Sonos tract binaries in versions earlier than 0.21.16, 0.22.2, and 0.23.1. Any application that loads NNEF archives—either via model_for_path or model_for_read—without validating tensor dimensions is susceptible. Alternative tensor paths for bool, String, or block‑quant remain protected and are not impacted by this issue.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity. The EPSS score is < 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low to moderate exploitation probability once exposed. The attack requires the attacker to supply a malicious NNEF model file; therefore, the likely vector is local or within an environment that accepts untrusted model inputs. The impact includes sensitive data leakage from memory and potential service disruption through crashes, but not remote code execution.
OpenCVE Enrichment
Github GHSA