Impact
The vulnerability resides in the Tensor::from_raw_dt_align function of the ONNX Initializer Loader in sonos tract through 0.23.4. When processing a crafted tensor, the function calculates an incorrect buffer size, which can lead to a buffer overflow via unsafe memory writes. This flaw allows an attacker to corrupt adjacent memory, potentially causing crashes or enabling arbitrary code execution, and is considered a remote memory corruption vulnerability.
Affected Systems
The affected product is sonos tract version 0.23.4 and earlier. The vulnerability is tied to the sonos tract code base as indicated by the product name and the CPE string. The commit 66b10bda8895f4bfaf8c205361f0125cdf51f99b provides the fix. Users running any legacy sonos tract releases should be aware that the issue persists until the patch is applied.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate severity. The EPSS score is not available, and the vulnerability is currently not listed in CISA’s KEV catalog. However, the description confirms that the exploit can be launched remotely and has been publicly disclosed, suggesting that attackers with network access to the affected component could potentially trigger the overflow and exploit the error.
OpenCVE Enrichment