Downloads · 30 days
0
Talson/mfv-tflite-offset-overflow
mfv-tflite-offset-overflow is a machine learning model from Talson. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as mit.
Vulnerability Class: CWE-190 Integer Overflow → CWE-125 Out-of-bounds Read Affected: tensorflow/tensorflow (TFLite interpreter) @ HEAD Status: ASAN-verified (3 variants: SEGV, heap-buffer-overflow READ)
Downloads · 30 days
0
Access
Public
Updated Jun 12, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.md11.9 KB · 35%
From the Hugging Face model README
Vulnerability Class: CWE-190 Integer Overflow → CWE-125 Out-of-bounds Read
Affected: tensorflow/tensorflow (TFLite interpreter) @ HEAD
Status: ASAN-verified (3 variants: SEGV, heap-buffer-overflow READ)
Integer overflow in TFLite InterpreterBuilder at interpreter_builder.cc:671 —
offset + buffer->size() wraps uint64_t, bypassing the bounds check. The resulting
pointer allocation_->base() + offset goes OOB. Same pattern at line 378 for
large_custom_options_offset + large_custom_options_size.
Key factor: InterpreterBuilder does NOT invoke the flatbuffer verifier by default.
Even the optional verifier does not validate Buffer.offset/Buffer.size fields.
poc/harness_tflite_offset.cpp — Self-contained ASAN harness (3 modes)evidence/buffer_offset_segv.txt — ASAN log: OOB pointer accessevidence/large_custom_options_oob.txt — ASAN log: heap-buffer-overflow READevidence/buffer_offset_heap_oob.txt — ASAN log: heap-buffer-overflow variantREPORT.md — Full vulnerability reportg++ -std=c++17 -fsanitize=address -g -O0 -o harness_tflite poc/harness_tflite_offset.cpp
./harness_tflite # Buffer offset overflow → OOB
./harness_tflite custom # large_custom_options overflow → heap OOB
./harness_tflite heap # near-end offset → heap-buffer-overflow READ