CVE-2026-11329

Publication date 8 June 2026

Last updated 10 June 2026


Ubuntu priority

Cvss 3 Severity Score

3.6 · Low

Score breakdown

Description

A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the component Placeholder Node Cache Handler. Such manipulation leads to use of weak hash. An attack has to be approached locally. A high complexity level is associated with this attack. The exploitation is known to be difficult. The name of the patch is 72c5187ff6d13c2c2b3d3789b8f5faf99f08a5b4. Applying a patch is advised to resolve this issue.

Read the notes from the security team

Status

Package Ubuntu Release Status
onnx 26.04 LTS resolute
Not affected
25.10 questing
Not affected
24.04 LTS noble
Not affected
22.04 LTS jammy
Not affected

Notes


federicoquattrin

This CVE affects onnx-mlir. ONNX is not affected.

Severity score breakdown

CVSS version:

Base score 2.0 · Low

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Base score 3.6 · Low

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L


Access our resources on patching vulnerabilities