Executive brief
OneFlow is an open-source deep learning framework used to build and deploy artificial intelligence models. A flaw in how the software handles memory allocation requests allows an attacker to crash the application by providing invalid input values. This results in a denial-of-service, potentially disrupting AI research, model training, or production inference services.
Technical details
A vulnerability exists in the flow.empty() component of OneFlow 0.9.0 due to insufficient validation of dimension parameters. When the function receives a negative or excessively large dimension value, it triggers a dimension mismatch check failure (CheckInplace) within the underlying C++ engine. This leads to a SIGABRT signal and a core dump, resulting in a complete crash of the process. The attack can be executed remotely if the application exposes an interface that passes user-supplied integers to the flow.empty() function. As of the advisory, the issue was identified in version 0.9.0.
Affected products
- OneFlow-Inc OneFlow 0.9.0
Timeline
- 2025-06-30: disclosed: Issue reported on GitHub repository
- 2026-01-28: advisory: CVE published to NVD