Executive brief
ArmNN is a software library used to accelerate machine learning on ARM-based devices. A vulnerability in how it processes certain model files could allow an attacker to crash an application or cause it to behave unexpectedly by providing a specially crafted TFLite model. This could impact the reliability and availability of services relying on machine learning inference.
Technical details
An integer overflow vulnerability exists in TensorShape::GetNumElements() within armnn/Tensor.cpp. The flaw occurs when multiplying tensor dimensions using 32-bit unsigned arithmetic without sufficient overflow detection. This causes GetNumBytes() to return an understated allocation size, leading to a heap-based buffer over-read during the model optimization phase, specifically within the BatchToSpaceNdLayer during the Optimize()->InferOutputShapes() call. An attacker can exploit this by providing a malicious TFLite model file. The vulnerability is triggered locally and can lead to a denial of service (application crash).
Affected products
- Arm ArmNN through 2026-03-27
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory