Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 26 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Overflow in ArmNN Tensor Shape Causes Buffer Over‑read |
Tue, 26 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
cvssV3_1
|
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arm
Arm armnn |
|
| Vendors & Products |
Arm
Arm armnn |
Fri, 22 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Overflow in ArmNN Tensor Shape Causes Buffer Over‑read | |
| Weaknesses | CWE-126 CWE-680 |
Fri, 22 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model optimization. The overflow occurs when multiplying tensor dimensions using 32-bit unsigned arithmetic without overflow detection, causing GetNumBytes() to return an understated allocation size. During Optimize()->InferOutputShapes(), the BatchToSpaceNdLayer reads beyond the allocated buffer. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-26T15:16:51.610Z
Reserved: 2026-04-29T00:00:00.000Z
Link: CVE-2026-42627
Updated: 2026-05-26T15:16:48.765Z
Status : Deferred
Published: 2026-05-22T18:16:22.593
Modified: 2026-06-17T10:48:11.943
Link: CVE-2026-42627
No data.
OpenCVE Enrichment
Updated: 2026-05-26T18:00:14Z