CVE-2024-27319

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
23/02/2024
Last modified:
13/02/2025

Description

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:* 1.16.0 (excluding)
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*