Junglewise Threat Intelligence

CVE-2026-42627: Arm ArmNN integer overflow in TensorShape::GetNumElements

CVE-2026-42627 · Severity: medium · CVSS 6.2 · Published 2026-05-22

Vendors: Arm.

Executive brief

ArmNN is a software library used to accelerate machine learning on ARM-based devices. A vulnerability in how it processes certain model files could allow an attacker to crash an application or cause it to behave unexpectedly by providing a specially crafted TFLite model. This could impact the reliability and availability of services relying on machine learning inference.

Technical details

An integer overflow vulnerability exists in TensorShape::GetNumElements() within armnn/Tensor.cpp. The flaw occurs when multiplying tensor dimensions using 32-bit unsigned arithmetic without sufficient overflow detection. This causes GetNumBytes() to return an understated allocation size, leading to a heap-based buffer over-read during the model optimization phase, specifically within the BatchToSpaceNdLayer during the Optimize()->InferOutputShapes() call. An attacker can exploit this by providing a malicious TFLite model file. The vulnerability is triggered locally and can lead to a denial of service (application crash).

Affected products

  • Arm ArmNN through 2026-03-27

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory

References