PT-2026-76902 · Sonos · Sonos Tract

·

CVE-2026-75093

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions sonos tract versions prior to 0.23.5
Description A flaw in the ONNX Initializer Loader component allows for remote attacks. The issue resides in the Tensor::from raw dt align() function within the data/src/tensor.rs file, where improper manipulation leads to an incorrect calculation of the buffer size.
Recommendations Apply patch 66b10bda8895f4bfaf8c205361f0125cdf51f99b to resolve the issue.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75093

Affected Products

Sonos Tract