Executive brief
OneFlow is an open-source deep learning framework used for building and deploying artificial intelligence models. A flaw in its mathematical processing component allows an attacker to crash the software by providing a specific type of invalid data. This results in a denial-of-service, potentially interrupting AI training or inference tasks and impacting service availability.
Technical details
A division-by-zero vulnerability (CWE-369) exists in the 'flow.floor_divide()' function of OneFlow version 0.9.0. The issue is triggered when the function receives a divisor tensor containing zero values, which leads to a floating-point exception and a subsequent core dump. An attacker can exploit this by providing specially crafted input tensors to an application utilizing this framework. This results in a complete crash of the process (Denial of Service). The vulnerability is reachable over the network if the application exposes an interface that processes user-supplied tensors.
Affected products
- Oneflow-Inc OneFlow 0.9.0
Timeline
- 2025-06-30: disclosed: Issue reported on GitHub repository
- 2026-01-28: advisory: NVD publication date