Skip to main content
EPSS 0.6%top 54%

CVE-2026-75093: Incorrect Calculation of Buffer Size in sonos tract

0
Medium
VulnerabilityCVE-2026-75093cvecve-2026-75093
Published: 08/18/2026 (08/18/2026, 01:30:12 UTC)
Source: CVE Database V5
Vendor/Project: sonos
Product: tract

Description

CVE-2026-75093 is a medium severity vulnerability in sonos tract up to version 0.23.4. It involves an incorrect calculation of buffer size in the function Tensor::from_raw_dt_align within the ONNX Initializer Loader component. The vulnerability can be exploited remotely and requires user interaction. A patch identified by commit 66b10bda8895f4bfaf8c205361f0125cdf51f99b is available to fix this issue.

CVSS v4.0

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Passive
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

Affected software

sonos

tract

Affected versions
=0.23.0=0.23.1=0.23.2=0.23.3=0.23.4
crates.iomore threats →ai
github/sonos/tract
pkg:cargo/github/sonos/tract
Affected versions
=0.23.0=0.23.1=0.23.2=0.23.3=0.23.4
CPE configurations
cpe:2.3:a:sonos:tract:*:*:*:*:*:*:*:*

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 23:32:21 UTC

Technical Analysis

This vulnerability affects sonos tract versions 0.23.0 through 0.23.4. It arises from an incorrect calculation of buffer size in the function Tensor::from_raw_dt_align in the file data/src/tensor.rs, part of the ONNX Initializer Loader component. The flaw allows remote attackers to manipulate the buffer size calculation, potentially leading to security issues. The vulnerability has a CVSS 4.0 base score of 5.3, indicating medium severity, with attack vector network, low attack complexity, no privileges required, and user interaction needed. A patch identified by commit 66b10bda8895f4bfaf8c205361f0125cdf51f99b is recommended to resolve the issue.

Potential Impact

The vulnerability allows remote attackers to cause incorrect buffer size calculations, which may lead to memory corruption or other unintended behavior. The CVSS score of 5.3 reflects a medium impact with limited scope and no privileges required. Exploitation requires user interaction. There is no indication of active exploitation in the wild.

Mitigation Recommendations

A patch identified by commit 66b10bda8895f4bfaf8c205361f0125cdf51f99b is available and should be applied to affected versions to remediate this vulnerability. Applying this patch is the best practice to resolve the issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulDB
Date Reserved
2026-08-17T16:39:53.532Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a83bbd9bf8831d539fd2400

Added to database: 08/18/2026, 01:56:41 UTC

Last enriched: 09/11/2026, 23:32:21 UTC

Last updated: 10/02/2026, 02:46:06 UTC

Views: 71

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses