Downloads · 30 days
0
WolfpackArmy/openvino-ir-integer-overflow-poc
openvino-ir-integer-overflow-poc is a machine learning model from WolfpackArmy. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Integer overflow in offset+size bounds check in xmldeserializeutil.cpp.
Downloads · 30 days
0
Access
Public
Updated Apr 12, 2026
Repo size
256 B
Likes
0
Public
Click a slice to open those files.
.xml2.3 KB · 44%
From the Hugging Face model README
Integer overflow in offset+size bounds check in xml_deserialize_util.cpp.
overflow_model.xml - Crafted IR model with overflow offset/size in Const layeroverflow_model.bin - Minimal weights file (256 bytes)import openvino as ov
core = ov.Core()
model = core.read_model("overflow_model.xml", "overflow_model.bin")
# Triggers integer overflow: offset(0xFFFFFFFFFFFFFF00) + size(0x200) = 0x100
# Bounds check passes (0x100 <= 256), but offset is far out of bounds
The bounds check m_weights->size() < offset + size uses unchecked addition.
With offset=0xFFFFFFFFFFFFFF00 and size=0x200, the sum wraps to 0x100 (256),
which equals the .bin file size, so the check passes.
The subsequent get_ptr<char>() + offset creates an out-of-bounds pointer.
Replace offset + size with overflow-safe check:
if (offset > m_weights->size() || size > m_weights->size() - offset)
OPENVINO_THROW("Incorrect weights in bin file!");