Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 39: FEDORA-2024-270e3b5e9b critical: onnx Directory Traversal

fedora
Calendar Grey March 29, 2024
Dist Fedora Esm H88
Critical security patch released for onnx on Fedora, resolving severe directory traversal vulnerabilities and memory access concerns.
Security fix for CVE-2024-27318 and CVE-2024-27319

Summary

onnx provides an open source format for AI models, both deep learning and

traditional ML. It defines an extensible computation graph model, as well as

definitions of built-in operators and standard data types.

Update Information:

Security fix for CVE-2024-27318 and CVE-2024-27319

Change Log

* Wed Mar 20 2024 Alejandro Alvarez Ayllon - 1.14.0-9 - Backport of fixes for CVE-2024-27318 and CVE-2024-27319

References


[ 1 ] Bug #2265737 - CVE-2024-27318 onnx: directory traversal https://bugzilla.redhat.com/show_bug.cgi?id=2265737 [ 2 ] Bug #2265739 - CVE-2024-27319 onnx: oob read https://bugzilla.redhat.com/show_bug.cgi?id=2265739

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-270e3b5e9b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: onnx
Product: Fedora 39
Version: 1.14.0
Release: 9.fc39
Summary: Open standard for machine learning interoperability

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here