Downloads · 30 days
6
4% of all-time downloads
AgentRen/gguf-security-poc
gguf-security-poc is a machine learning model from AgentRen. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
These are proof-of-concept files demonstrating vulnerabilities in GGML's GGUF parser.
Downloads · 30 days
6
4% of all-time downloads
All-time downloads
143
Public
Repo size
—
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 61%
From the Hugging Face model README
These are proof-of-concept files demonstrating vulnerabilities in GGML's GGUF parser.
Integer overflow in tensor stride (nb[]) calculations. A tensor with ne[0]=2^62 and type F32 causes nb[1] = 4 * 2^62 = 2^64 which overflows size_t to 0. This bypasses the SIZE_MAX overflow check, resulting in a 0-byte allocation for a tensor claiming 2^62 elements. Any access to tensor data is a heap buffer overflow.
Division by zero at gguf.cpp:550 when ne[1]=0 with n_dims>=2. The element overflow check computes INT64_MAX/ne[1] which is undefined behavior. Causes SIGFPE crash on x86.
Tested against: ggml commit a8db410 compiled with AddressSanitizer.