Downloads · 30 days
17
18% of all-time downloads
aTmHnTR/gguf-array-overflow-poc
gguf-array-overflow-poc is a machine learning model from aTmHnTR. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for llama.cpp. The card lists the license as mit.
This repository contains an intentionally malformed GGUF file created to demonstrate unsafe behavior in GGUF metadata parsing within llama.cpp.
Downloads · 30 days
17
18% of all-time downloads
All-time downloads
97
Public
Repo size
—
Likes
0
Public
Click a slice to open those files.
.md2.6 KB · 61%
From the Hugging Face model README
This repository contains an intentionally malformed GGUF file created to demonstrate unsafe behavior in GGUF metadata parsing within llama.cpp.
This file is not a machine learning model. It is malformed by design and must not be used for inference or production.
The artifact exists solely for responsible security research, reproducibility, and validation by maintainers and Huntr’s Model File Vulnerability (MFV) triage team.
A minimized GGUF payload (~64 bytes) that triggers load-time undefined behavior during GGUF metadata parsing.
The file was minimized using AFL++ (afl-tmin) to produce a stable, deterministic reproducer.
Malformed, attacker-controlled metadata values are propagated into GGUF parsing logic, resulting in unsafe arithmetic and undefined behavior during model loading.
This PoC demonstrates:
gguf.cppThe demonstrated impact is load-time undefined behavior / denial of service. No claims of memory corruption beyond this are made.
When scanned using ProtectAI modelscan, the file reports no issues, despite reliably triggering load-time undefined behavior when parsed by llama.cpp.
Scanner evidence is provided in the associated Huntr submission comments.
This artifact is intended only for:
This file must not be:
This repository is part of a Huntr Model File Vulnerability (MFV) disclosure.
It does not correspond to a research model, dataset, or paper.
All vulnerability coordination must occur through Huntr’s MFV reporting system. Public discussion should avoid vulnerability details.