PT-2026-76902 · Sonos · Sonos Tract
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
sonos tract versions prior to 0.23.5
Description
A flaw in the ONNX Initializer Loader component allows for remote attacks. The issue resides in the
Tensor::from raw dt align() function within the data/src/tensor.rs file, where improper manipulation leads to an incorrect calculation of the buffer size.Recommendations
Apply patch 66b10bda8895f4bfaf8c205361f0125cdf51f99b to resolve the issue.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sonos Tract