Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 40: Update for ONNX 1.14.1 Critical Security Issues

fedora
Calendar Grey March 29, 2024
Dist Fedora Esm H88
Fedora 40's latest ONNX update tackles critical security issues, including CVE-2024-27318 and CVE-2024-27319. Ensure system security by following the installation guidelines provided below
Security fix for CVE-2024-27318 and CVE-2024-27319

Summary

onnx provides an open source format for AI models, both deep learning and

traditional ML. It defines an extensible computation graph model, as well as

definitions of built-in operators and standard data types.

Update Information:

Security fix for CVE-2024-27318 and CVE-2024-27319

Change Log

* Sat Feb 24 2024 Alejandro Alvarez Ayllon - 1.14.1-2 - Backport of fixes for CVE-2024-27318 and CVE-2024-27319 * Wed Feb 21 2024 Diego Herrera C - 1.14.1-1 - Release 1.14.1

References


[ 1 ] Bug #2265737 - CVE-2024-27318 onnx: directory traversal https://bugzilla.redhat.com/show_bug.cgi?id=2265737 [ 2 ] Bug #2265739 - CVE-2024-27319 onnx: oob read https://bugzilla.redhat.com/show_bug.cgi?id=2265739

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-abe1e34fdb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: onnx
Product: Fedora 40
Version: 1.14.1
Release: 2.fc40
URL:
Summary: Open standard for machine learning interoperability

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here