CVE-2026-75093: sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size

Published Aug 18, 2026
·
Updated

A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::fromrawdtalign of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 66b10bda8895f4bfaf8c205361f0125cdf51f99b. It is best practice to apply a patch to resolve this issue.

Affected Software

2 affected components
sonos/tract<=0.23.4
sonos/tract/ONNX Initializer Loader

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade sonos tract / ONNX Initializer Loader (Tensor::from_raw_dt_align, data/src/tensor.rs) to a version that resolves this vulnerability.

    Patch 66b10bda8895f4bfaf8c205361f0125cdf51f99b

Event History

Aug 18, 2026
CVE Published
via MITRE·01:30 AM
Data Sourced
via MITRE·01:30 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using sonos tract up to version 0.23.4 are affected where the ONNX Initializer Loader processes attacker-manipulated input. The issue can be launched remotely, and no privileges are required, but user interaction is required according to the supplied severity vector.

2

What does exploitation require?

An attacker needs to cause processing of manipulated data through the ONNX Initializer Loader, targeting Tensor::from_raw_dt_align in data/src/tensor.rs. Public exploit disclosure is available, increasing the likelihood of exploitation attempts.

3

What is the available remediation?

Apply patch 66b10bda8895f4bfaf8c205361f0125cdf51f99b. If patching cannot occur immediately, the provided information does not specify an alternative mitigation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203