CVE-2024-27319: Critical severity linuxfoundation Onnx vulnerability
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNXASSERT and ONNXASSERTM functions have an off by one string copy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/onnxto a version that resolves this vulnerability.Fixed in 1.16.0 - Upgrade
Upgrade
onnxto a version that resolves this vulnerability.Fixed in 1.15.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27319?
CVE-2024-27319 is classified as a moderate severity vulnerability due to its potential for causing out-of-bounds read issues.
How do I fix CVE-2024-27319?
To fix CVE-2024-27319, upgrade the ONNX package to version 1.16.0 or later.
Which versions are affected by CVE-2024-27319?
CVE-2024-27319 affects ONNX package versions before and including 1.15.0.
What types of attacks can CVE-2024-27319 enable?
CVE-2024-27319 may enable attackers to exploit out-of-bounds read vulnerabilities, potentially leading to information disclosure.
Is my system vulnerable to CVE-2024-27319?
If you are using ONNX version 1.15.0 or earlier, your system is vulnerable to CVE-2024-27319.