Skip to content

CVE-2026-14647: one loop, two lengths

CVE-2026-14647 mechanism diagram

The crafted 255-byte ModelProto makes the input tensor rank 4 and the weight tensor rank 5, with no explicit kernel_shape. convPoolShapeInference therefore creates a two-element dilations vector from the input's spatial rank but derives a three-element kernel_shape from the weight. The loop is bounded by the latter and indexes the former: iteration 2 reads dilations[2] beyond the allocation.

What the evidence supports

  • The fault is an 8-byte heap out-of-bounds read during Load(), before inference.
  • It is not an out-of-bounds write and the diagram does not imply code execution.
  • ONNX PR #8037 fixes the invariant by validating the weight-derived kernel shape against the input spatial rank.
  • Our proposed score was 7.5 High; the assigner recorded CVSS v3.1 4.3 / v4.0 5.3. Both remain visible because provenance matters more than forcing agreement.

The CVE identity, primitive, scores, and public reference are read from the canonical ledger when this SVG is generated. Mechanism-specific facts come from the public CRUCIBLE-2026-086 advisory. Run go run ./tools/cveviz after either source changes; --check refuses stale output.

See the public CVE catalog for the complete disclosed set.