Downloads · 30 days
13
7% of all-time downloads
kevintsai1202/gguf-offset-overflow-poc
gguf-offset-overflow-poc is a machine learning model from kevintsai1202. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as mit.
Security Research Only — Do NOT use this model for inference
Downloads · 30 days
13
7% of all-time downloads
All-time downloads
178
Public
Repo size
—
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 45%
From the Hugging Face model README
Security Research Only — Do NOT use this model for inference
gguf (PyPI, part of llama.cpp)gguf_reader.py, line 333data_offs = int(start_offs + offset_tensor[0])offset_tensor[0] is read as numpy.uint64 directly from the GGUF file.
When set to UINT64_MAX (0xFFFFFFFFFFFFFFFF), the addition overflows numpy's
uint64 arithmetic (wraps mod 2^64), causing the tensor to be silently loaded
from the wrong file offset.
import warnings
from gguf import GGUFReader
with warnings.catch_warnings(record=True) as w:
warnings.simplefilter("always")
reader = GGUFReader("evil.gguf")
for warning in w:
if "overflow" in str(warning.message).lower():
print(f"CONFIRMED: {warning.message}")
print(f"at: {warning.filename}:{warning.lineno}")
Expected output:
CONFIRMED: overflow encountered in scalar add
at: .../gguf/gguf_reader.py:333
This Python-layer integer overflow is not covered by existing CVEs.
Uploaded by kevintsai1202 for responsible disclosure via Huntr.