Downloads · 30 days
0
UNILESS/armnn-deserializer-poc-cwe787
armnn-deserializer-poc-cwe787 is a machine learning model from UNILESS. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
This repository contains a single proof-of-concept file, poc.armnn (296 bytes), used for coordinated disclosure of a stack-based buffer overflow in the Arm NN deserializer (armnnDeserializer::ToTensorInfo). It is a se…
Downloads · 30 days
0
Access
Public
Updated Jul 19, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.md1.6 KB · 47%
From the Hugging Face model README
This repository contains a single proof-of-concept file, poc.armnn (296 bytes), used for coordinated disclosure of a stack-based buffer overflow in the Arm NN deserializer (armnnDeserializer::ToTensorInfo). It is a security research artifact. Loading the file triggers a memory-safety crash during deserialization. It performs no code execution and has no effect other than crashing the process that loads it.
poc.armnn: a serialized Arm NN graph (armnnSerializer flatbuffers schema) with a single InputLayer whose output tensor declares a dimensionSpecificity vector of length 64. The deserializer copies that vector into a fixed 5-element stack array (bool[armnn::MaxNumOfTensorDimensions]) without a bounds check.Loading the file through the public deserializer API crashes:
auto d = armnnDeserializer::IDeserializer::Create();
d->CreateNetworkFromBinary(bytes_of_poc_armnn); // stack-buffer-overflow in ToTensorInfo
Under AddressSanitizer this reports a stack-buffer-overflow WRITE in armnnDeserializer::ToTensorInfo (Deserializer.cpp:756), reached from CreateNetworkFromBinary -> CreateNetworkFromGraph -> SetupInputLayers -> ToTensorInfo. The file is a structurally valid flatbuffers buffer and passes the deserializer's Verifier.
This file only crashes the loader. Do not load it with an Arm NN build you depend on. It is intended for controlled reproduction of the vulnerability during disclosure.