{"id":"PYSEC-2026-2689","summary":"ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)","details":"### Summary\n\nNull pointer dereference (SIGSEGV) in `Upsample_6_7::adapt_upsample_6_7()` (`onnx/version_converter/adapters/upsample_6_7.h:31`) when `convert_version()` processes a model with an Upsample node that has zero inputs. The adapter accesses `node-\u003einputs()[0]-\u003esizes()` without checking input count. 107-byte PoC crashes on Release build.\n\nThis is the same class of bug as the Cast adapter advisory (separate report) but in a different adapter, different file, and different operator.\n\n### Details\n\nThe Upsample 6→7 adapter validates attributes but not inputs:\n```cpp\n// upsample_6_7.h:20-33\nvoid adapt_upsample_6_7(..., Node* node) const {\n    ONNX_ASSERTM(\n        node-\u003ehasAttribute(width_scale_symbol) && node-\u003ehasAttribute(height_scale_symbol),\n        \"...\")  // Attribute check PASSES\n\n    auto width_scale = node-\u003ef(width_scale_symbol);\n    auto height_scale = node-\u003ef(height_scale_symbol);\n\n    auto input_shape = node-\u003einputs()[0]-\u003esizes();\n    //                 ^^^^^^^^^^^^^^^^^^^^\n    //                 OOB when inputs().size() == 0 → SIGSEGV\n}\n```\n\nThe PoC has an Upsample node at opset 6 with the required `width_scale` and `height_scale` attributes but zero inputs. The attribute assertions pass, then `node-\u003einputs()[0]` on an empty `ArrayRef`:\n- Release builds (`NDEBUG`): bounds-check assertion compiled out → reads garbage pointer → SIGSEGV\n- Debug builds: `assert(Index \u003c Length)` at `array_ref.h:159` → SIGABRT\n\nAn Upsample node with zero inputs passes `graphProtoToGraph()` because the import code only resolves input names present in the protobuf.\n\n### PoC\n```python\nimport base64\nimport onnx\nfrom onnx import version_converter\n\npoc_b64 = \"CAI6YQo8EgFZIghVcHNhbXBsZSoVCgt3aWR0aF9zY2FsZRUAAABAoAEBKhYKDGhlaWdodF9zY2FsZRUAAABAoAEBEgR0ZXN0YhsKAVkSFgoUCAESEAoCCAEKAggBCgIIBAoCCARCBAoAEAY=\"\n\nmodel = onnx.load_from_string(base64.b64decode(poc_b64))\n\n# CRASHES — Upsample_6_7 adapter dereferences empty inputs array\nversion_converter.convert_version(model, 7)  # SIGSEGV\n```\n\n107-byte PoC. Confirmed SIGSEGV on both onnx 1.21.0 (pip) and 1.22.0 (source build).\n\n### Impact\n\nAny application that uses `onnx.version_converter.convert_version()` on untrusted models is vulnerable. This includes model conversion pipelines and tools that auto-upgrade opset versions for compatibility. The crash is unrecoverable (SIGSEGV). \n\nThis vulnerability is part of a systemic pattern across multiple version converter adapters. A full audit of all ~45 adapters was performed as part of the fix; eight adapters were found with the same class of unguarded indexed access (cast_9_8, softmax_12_13, softmax_13_12, upsample_6_7, upsample_9_10, group_normalization_20_21, broadcast_forward_compatibility, upsample_9_8) and all have been fixed in PR #7813.","aliases":["CVE-2026-44512","GHSA-hwpq-hmq9-wj77"],"modified":"2026-07-13T16:32:54.590029640Z","published":"2026-07-13T15:46:29.073664Z","references":[{"type":"WEB","url":"https://github.com/onnx/onnx/security/advisories/GHSA-hwpq-hmq9-wj77"},{"type":"WEB","url":"https://github.com/onnx/onnx/pull/7916"},{"type":"PACKAGE","url":"https://github.com/onnx/onnx"},{"type":"WEB","url":"https://github.com/onnx/onnx/releases/tag/v1.22.0"},{"type":"PACKAGE","url":"https://pypi.org/project/onnx"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hwpq-hmq9-wj77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44512"}],"affected":[{"package":{"name":"onnx","ecosystem":"PyPI","purl":"pkg:pypi/onnx"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.9.0"},{"fixed":"1.22.0"}]}],"versions":["1.10.0","1.10.1","1.10.2","1.11.0","1.12.0","1.13.0","1.13.1","1.14.0","1.14.1","1.15.0","1.16.0","1.16.1","1.16.2","1.17.0","1.18.0","1.19.0","1.19.1","1.19.1rc1","1.20.0","1.20.0rc1","1.20.0rc2","1.20.1","1.20.1rc1","1.21.0","1.21.0rc1","1.21.0rc2","1.21.0rc3","1.21.0rc4","1.22.0rc1","1.22.0rc2","1.9.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/onnx/PYSEC-2026-2689.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}