CVE-2026-75093 | sonos tract up to 0.23.4 ONNX Initializer Loader data/src/tensor.rs from_raw_dt_align buffer size (Issue 2390)

SecurityVulns

A vulnerability was found in sonos tract up to 0.23.4. It has been declared as problematic. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size.

This vulnerability is traded as CVE-2026-75093. The attack may be launched remotely. Furthermore, there is an exploit available.

It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More