What is CVE-2026-75093?
CVE-2026-75093 is a vulnerability in 'sonos tract' up to version 0.23.4, affecting the 'Tensor::from_raw_dt_align' function in the ONNX Initializer Loader component's 'data/src/tensor.rs' file. It leads to incorrect buffer size calculation, potentially allowing remote attacks. Users should update to the latest version immediately.
Azərbaycanca: CVE-2026-75093, 'sonos tract' kitabxanasının 0.23.4 versiyasına qədər olan versiyalarında, ONNX Initializer Loader komponentindəki 'Tensor::from_raw_dt_align' funksiyasında bufer ölçüsünün səhv hesablanması zəifliyidir. Bu, uzaqdan hücum edənə təsir göstərə bilər. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
FAQ2
In which component of the 'sonos tract' library was CVE-2026-75093 discovered?
This vulnerability was discovered in the 'Tensor::from_raw_dt_align' function within the ONNX Initializer Loader component of the 'sonos tract' library.
What action is recommended to users to protect against CVE-2026-75093?
Users are recommended to immediately update the 'sonos tract' library to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.