Junglewise Threat Intelligence

CVE-2025-71001: Oneflow-Inc OneFlow segmentation fault in flow.column_stack

CVE-2025-71001 · Severity: medium · CVSS 6.5 · Published 2026-01-28

Technologies: Oneflow. Vendors: Oneflow.

Executive brief

OneFlow is an open-source deep learning framework used for building and training machine learning models. A flaw in how the software handles specific data inputs can cause the application to crash unexpectedly. This could allow an attacker to disrupt services or research activities by providing a specially crafted data file that triggers a system failure.

Technical details

A segmentation fault (CWE-125) exists in the flow.column_stack component of OneFlow v0.9.0. The vulnerability is triggered when the API attempts to process a list containing a mix of OneFlow tensors and NumPy arrays, leading to a type mismatch or invalid memory access. An attacker can exploit this by providing crafted input that causes the process to crash (core dump), resulting in a denial of service. The issue is confirmed in version 0.9.0 when running on environments such as Ubuntu 22.04 with Python 3.10.

Affected products

  • Oneflow-Inc OneFlow 0.9.0

Timeline

  • 2025-06-30: disclosed: Issue reported on GitHub repository
  • 2026-01-28: advisory: NVD published CVE-2025-71001

References

Related threats