Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
| Software | From | Fixed in |
|---|---|---|
onnx
|
- | 1.16.0 |
| linuxfoundation / onnx | - | 1.16.0 |
| fedoraproject / fedora | 39 | 39.x |
| fedoraproject / fedora | 40 | 40.x |