Downloads · 30 days
0
0xiviel/poc-pytorch-recordoffset
poc-pytorch-recordoffset is a machine learning model from 0xiviel. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Vulnerability: inlinecontainer.cc:634-637 — getRecordOffset() reads filenamelen and extralen from the ZIP local file header without cross-validating against the central directory. A crafted .pt file with modified loca…
Downloads · 30 days
0
Access
Public
Updated Feb 13, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.py17.2 KB · 87%
From the Hugging Face model README
Vulnerability: inline_container.cc:634-637 — getRecordOffset() reads filename_len and extra_len from the ZIP local file header without cross-validating against the central directory. A crafted .pt file with modified local header fields causes the function to return a wrong offset, leading to OOB access, silent data corruption, or DoS via torch.load(mmap=True). On 32-bit platforms, mz_uint64 → size_t truncation silently wraps the offset.
poc_record_offset_overflow.py — Full PoC (wrong offset demo, mmap impact, within-file corruption, overflow analysis)pip install torch
python poc_record_offset_overflow.py
get_record_offset() returns 66175 for a 1563-byte file (past EOF by 64612 bytes)torch.load(mmap=True) fails with RuntimeError (DoS)