CVE-2026-75093
A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 66b10bda8895f4bfaf8c205361f0125cdf51f99b. It is best practice to apply a patch to resolve this issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.34%
- CWE
- CWE-131, CWE-120
- Published
- 2026-08-18
- Last modified
- 2026-08-19
Affected products
- sonos tract
- sonos tract
- sonos tract
- sonos tract
- sonos tract
Weakness type
Related vulnerabilities
- CVE-2026-22590 — Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG sampleSize / fragmentsInSubmessage
- CVE-2026-69598 — Windows iSCSI Remote Code Execution Vulnerability
- CVE-2026-78221 — An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1...
- CVE-2026-18743 — Popt-devel: popt-static: short realloc in poptconfigfiletostring
- CVE-2026-78002 — Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function
- CVE-2026-44254 — Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path
- CVE-2026-52834 — jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platforms
- CVE-2026-70457 — rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()