{"id":"CVE-2024-27319","details":"Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.","aliases":["GHSA-h8wv-9h96-m4hr","PYSEC-2024-223"],"modified":"2026-08-12T15:15:08.192232Z","published":"2024-02-23T17:39:52.870Z","related":["CGA-rq6w-587w-q3v3","openSUSE-SU-2024:13803-1"],"database_specific":{"cna_assigner":"HiddenLayer","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27319.json"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27319.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27319"},{"type":"FIX","url":"https://github.com/onnx/onnx/commit/08a399ba75a805b7813ab8936b91d0e274b08287"},{"type":"PACKAGE","url":"https://github.com/onnx/onnx"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/onnx/onnx","events":[{"introduced":"0"},{"fixed":"990217f043af7222348ca8f0301e17fa7b841781"},{"fixed":"08a399ba75a805b7813ab8936b91d0e274b08287"}],"database_specific":{"cpe":"cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.16.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.3.0","v1.1.0","v0.2","v0.1"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:15:08Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/onnx/onnx/commit/08a399ba75a805b7813ab8936b91d0e274b08287","target":{"function":"barf","file":"onnx/common/assertions.cc"},"deprecated":false,"digest":{"function_hash":"150149194993235291064360914277493068496","length":190},"id":"CVE-2024-27319-015c0050"},{"digest":{"line_hashes":["101106728693998339951729822204693471475","208885074752424638675853475558295782158","331612258296014788007629159681433131682","315469259872839591120959177607505227360","170584720565874348943179677145476593174","320609885732320917201972430254444073524","213336569564941719947686272868626561565","113723751918112567312510435892577266575","134629294599338790974108607091807632424","276428317196113829494738400934358987720"],"threshold":0.9},"id":"CVE-2024-27319-544933c0","signature_type":"Line","signature_version":"v1","source":"https://github.com/onnx/onnx/commit/08a399ba75a805b7813ab8936b91d0e274b08287","target":{"file":"onnx/common/assertions.cc"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27319.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"}]}