#1143068 onnx: CVE-2026-14647

Package:
src:onnx
Source:
src:onnx
Submitter:
Salvatore Bonaccorso
Date:
2026-08-03 17:37:11 UTC
Severity:
normal
Tags:
#1143068#5
Date:
2026-07-30 05:25:44 UTC
From:
To:
Hi,

The following vulnerability was published for onnx.

CVE-2026-14647[0]:
| A weakness has been identified in onnx up to 1.21.x. This
| vulnerability affects the function convPoolShapeInference_opset19 of
| the file onnx/defs/nn/old.cc of the component onnxruntime. This
| manipulation causes out-of-bounds read. It is possible to initiate
| the attack remotely. The exploit has been made available to the
| public and could be used for attacks. Patch name:
| a7bf3a0f1d18bb62575236ef6e4944980c40e045. It is recommended to apply
| a patch to fix this issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14647
https://www.cve.org/CVERecord?id=CVE-2026-14647
[1] https://github.com/onnx/onnx/issues/8036
[2] https://github.com/onnx/onnx/pull/8051
[3] https://github.com/onnx/onnx/commit/a7bf3a0f1d18bb62575236ef6e4944980c40e045

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore