Downloads · 30 days
14
12% of all-time downloads
loowr/gguf-poc
gguf-poc is a machine learning model from loowr. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as mit.
The Python GGUF reader in llama.cpp's gguf-py library lacks the input validation bounds that the C++ implementation has, allowing a maliciously crafted GGUF file to cause denial of service through excessive memory all…
Downloads · 30 days
14
12% of all-time downloads
All-time downloads
121
Public
Repo size
—
Likes
1
Public
Click a slice to open those files.
Other1.5 KB · 35%
From the Hugging Face model README
The Python GGUF reader in llama.cpp's gguf-py library lacks the input
validation bounds that the C++ implementation has, allowing a maliciously
crafted GGUF file to cause denial of service through excessive memory
allocation or infinite looping.
The C++ parser caps string lengths and array counts at 1 GiB (GGUF_MAX_STRING_LENGTH, GGUF_MAX_ARRAY_ELEMENTS). The Python parser has no equivalent checks.
gguf-py/gguf/gguf_reader.pyaa50b2c2ae91326d5aad956ceeb015d1d48e626bmalicious_gguf.gguf -- a 44-byte file that declares 100 million key-value
pairs in its header, causing the parser to iterate endlessly.
pip install gguf numpy
python reproduce.py
Expected: the script hangs indefinitely trying to parse a 44-byte file.
Any Python application using GGUFReader on untrusted GGUF files is
affected. This includes CLI tools shipped with gguf-py and any application
that loads GGUF models from user-supplied paths.
Add the bounds checks from the C++ implementation to the Python reader: