Home ยป Database

AVID-2026-R1492

Description

Vulnerability CVE-2024-36732

Details

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.tensordot.

Reason for inclusion in AVID: CVE-2024-36732 describes a Denial of Service vulnerability in the OneFlow framework (v0.9.1) when processing an empty array with oneflow.tensordot. OneFlow is a machine learning framework used in AI model development and deployment, placing this issue squarely in the AI software stack. The vulnerability affects software components used to build/train/deploy AI systems, i.e., a supply-chain-relevant dependency. The impact is a security-related DoS. The report provides a specific CVE ID and description, offering sufficient signal.

References

Affected or Relevant Artifacts

  • Developer: n/a
  • Deployer: n/a
  • Artifact Details:
TypeName
Systemn/a

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-06-06
  • Version: 0.3.3
  • AVID Entry