Downloads · 30 days
38
28% of all-time downloads
treforbenbow/tensorrt-int4-heap-overflow
tensorrt-int4-heap-overflow is a machine learning model from treforbenbow. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for tensorrt. The card lists the license as mit.
A crafted ONNX model with an INT4/UINT4 tensor where int32data array exceeds the tensor shape causes a heap buffer overflow in TensorRT ONNX parser. The convertPackedInt32Data() function writes attacker-controlled dat…
Downloads · 30 days
38
28% of all-time downloads
All-time downloads
134
Public
Repo size
111 KB
Likes
0
Public
Click a slice to open those files.
.onnx111 KB · 91%
From the Hugging Face model README
A crafted ONNX model with an INT4/UINT4 tensor where int32_data array exceeds the tensor shape causes a heap buffer overflow in TensorRT ONNX parser. The convertPackedInt32Data() function writes attacker-controlled data past the end of a heap buffer.
python vuln011_int4_heap_overflow.py build python vuln011_int4_heap_overflow.py verify python vuln011_int4_heap_overflow.py crash
WeightsContext.cpp convertPackedInt32Data() writes nbytes=int32_data.size() bytes to a buffer allocated for (volume(shape)*4+4)/8 bytes. No bounds check. Attacker controls overflow length and content.