Downloads · 30 days
0
0xiviel/poc-pytorch-memoryread
poc-pytorch-memoryread is a machine learning model from 0xiviel. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Downloads · 30 days
0
Access
Public
Updated Feb 13, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.py9.3 KB · 64%
From the Hugging Face model README
Security research PoC.
caffe2::serialize::MemoryReadAdapter::read() performs memcpy(buf, data_+pos, n)
without checking pos+n <= size_. The size_ member is stored but never validated
in the read path, enabling heap buffer over-reads.
poc_memoryread_oob.py — Full PoC with ASAN proof + code path reachabilitytest_oob_read.cpp — Standalone C++ ASAN test# Run full PoC
python poc_memoryread_oob.py
# Or compile C++ test directly
g++ -fsanitize=address -g test_oob_read.cpp -o test_oob_read
./test_oob_read # ASAN: heap-buffer-overflow
All PyTorch versions (code has never had bounds checking). Tested on PyTorch 2.10.0.