5.5
CVE-2026-44512
- EPSS 0.18%
- Veröffentlicht 08.07.2026 19:32:04
- Zuletzt bearbeitet 13.07.2026 17:02:01
- CVE-Watchlists
- Unerledigt
ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an untrusted model with an Upsample node that has zero inputs, causing an unrecoverable denial of service. This issue is fixed in version 1.22.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linuxfoundation ≫ Onnx Version >= 1.9.0 < 1.22.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.082 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://github.com/onnx/onnx/security/advisories/GHSA-hwpq-hmq9-wj77
https://github.com/onnx/onnx/pull/7813
https://github.com/onnx/onnx/commit/cd310408165ad47c3cd7eb2b86cb5b80aa2e4fdf
https://github.com/onnx/onnx/releases/tag/v1.22.0