{"id":"CVE-2026-50144","summary":"ncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negative parameter id","details":"ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows an out-of-bounds heap write in ncnn::ParamDict::load_param() when Net::load_param() loads a malicious .param model file because the parsed parameter id is checked only against id \u003e= NCNN_MAX_PARAM_COUNT, allowing a negative id to index before the params[NCNN_MAX_PARAM_COUNT] array. This vulnerability is fixed by commit 5a0288f255daa6c3294f77109f67718e434ec020.","aliases":["GHSA-jxmc-3mv6-7pwr"],"modified":"2026-08-12T16:09:42.956507Z","published":"2026-07-15T20:04:07.099Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-129","CWE-20","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50144.json","unresolved_ranges":[{"extracted_events":[{"fixed":"5a0288f255daa6c3294f77109f67718e434ec020"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50144.json"},{"type":"ADVISORY","url":"https://github.com/Tencent/ncnn/security/advisories/GHSA-jxmc-3mv6-7pwr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50144"},{"type":"FIX","url":"https://github.com/Tencent/ncnn/commit/5a0288f255daa6c3294f77109f67718e434ec020"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tencent/ncnn","events":[{"introduced":"0"},{"fixed":"5a0288f255daa6c3294f77109f67718e434ec020"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"20260526"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["20260526","20260113","20250916","20250503","20250428","20241226","20240820","20240410","20240102","20231027","20230816","20230517","20230223","20221128","20220729","20220721","20220701","20220420","20220216","20211208","20211122","20210720","20210525","20210507","20210322","20210124","20201218","20201208","20200916","20200727","20200616","20200413","20200226","20200106","20191113","20190908","20190611","20190320","20181228","20180830","20180704","20180427","20180314","20180129","20171225","20171017","20170919","20170809","20170724"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50144.json","vanir_signatures_modified":"2026-08-12T16:09:42Z","vanir_signatures":[{"target":{"function":"ParamDict::load_param","file":"src/paramdict.cpp"},"deprecated":false,"digest":{"function_hash":"171297044334995494663078596060466133510","length":3618},"id":"CVE-2026-50144-103a1a0e","signature_type":"Function","signature_version":"v1","source":"https://github.com/tencent/ncnn/commit/5a0288f255daa6c3294f77109f67718e434ec020"},{"deprecated":false,"digest":{"line_hashes":["181853437630716551010737920368319553457","299637648197898981894720791795991685189","299458721291546431739895988765752750296","108422265294207834176307630156347872400","181853437630716551010737920368319553457","299637648197898981894720791795991685189","299458721291546431739895988765752750296","108422265294207834176307630156347872400"],"threshold":0.9},"id":"CVE-2026-50144-1def21a3","signature_type":"Line","signature_version":"v1","source":"https://github.com/tencent/ncnn/commit/5a0288f255daa6c3294f77109f67718e434ec020","target":{"file":"src/paramdict.cpp"}},{"signature_version":"v1","source":"https://github.com/tencent/ncnn/commit/5a0288f255daa6c3294f77109f67718e434ec020","target":{"file":"src/paramdict.cpp","function":"ParamDict::load_param_bin"},"deprecated":false,"digest":{"function_hash":"246336981704188830382479758241099552672","length":2403},"id":"CVE-2026-50144-8c88893a","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}]}