Downloads · 30 days
0
treforbenbow/tensorrt-crash-poc-onnx-extdata-offset
tensorrt-crash-poc-onnx-extdata-offset is a machine learning model from treforbenbow. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
A crafted ONNX model with an externaldata weight reference containing a negative offset value (-1) crashes TensorRT's engine builder with STATUSACCESSVIOLATION (0xC0000005 on Windows / SIGSEGV on Linux).
Downloads · 30 days
0
Access
Public
Updated Mar 7, 2026
Repo size
440 B
Likes
0
Public
Click a slice to open those files.
.py3.9 KB · 49%
From the Hugging Face model README
A crafted ONNX model with an external_data weight reference containing a negative
offset value (-1) crashes TensorRT's engine builder with STATUS_ACCESS_VIOLATION
(0xC0000005 on Windows / SIGSEGV on Linux).
build_serialized_network() (parse succeeds with no error)The ONNX external_data offset field is int64 in the protobuf spec. TensorRT's
WeightsContext.cpp::parseExternalWeights() does not validate the offset before
passing it to seekg(). Negative values cause undefined behavior in file I/O,
producing garbage weight data that crashes the builder during optimization.
All negative offsets crash. All offsets >= ~2^32 also crash.
| File | Description |
|---|---|
crash_offset_neg1.onnx | Malicious ONNX model (offset=-1) - CAUSES CRASH |
benign_offset_0.onnx | Benign ONNX model (offset=0) - builds normally |
weights.bin | Weight file (64 bytes, required by both models) |
reproduce.py | Reproduction script |
pip install tensorrt onnx numpy torch
python reproduce.py
[1] Benign model (offset=0):
benign: rc=0 BUILD_OK size=...
[2] Malicious model (offset=-1):
malicious: CRASH (STATUS_ACCESS_VIOLATION 0xC0000005)
[3] Reproducibility (5 runs):
run 1: CRASH (STATUS_ACCESS_VIOLATION 0xC0000005)
run 2: CRASH (STATUS_ACCESS_VIOLATION 0xC0000005)
...
Crash rate: 5/5
Any TensorRT pipeline that accepts untrusted ONNX models and compiles them will crash:
High (CVSS 3.1: 7.5 -- AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Potential for memory corruption escalation beyond DoS.