CVE-2026-75093: sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size
A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::fromrawdtalign of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 66b10bda8895f4bfaf8c205361f0125cdf51f99b. It is best practice to apply a patch to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sonos tract / ONNX Initializer Loader (Tensor::from_raw_dt_align, data/src/tensor.rs)to a version that resolves this vulnerability.Patch 66b10bda8895f4bfaf8c205361f0125cdf51f99b
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using sonos tract up to version 0.23.4 are affected where the ONNX Initializer Loader processes attacker-manipulated input. The issue can be launched remotely, and no privileges are required, but user interaction is required according to the supplied severity vector.
What does exploitation require?
An attacker needs to cause processing of manipulated data through the ONNX Initializer Loader, targeting Tensor::from_raw_dt_align in data/src/tensor.rs. Public exploit disclosure is available, increasing the likelihood of exploitation attempts.
What is the available remediation?
Apply patch 66b10bda8895f4bfaf8c205361f0125cdf51f99b. If patching cannot occur immediately, the provided information does not specify an alternative mitigation.