Downloads · 30 days
0
ybgwon96/koboldcpp-legacy-ndims-stack-oob-poc
koboldcpp-legacy-ndims-stack-oob-poc is a machine learning model from ybgwon96. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as mit.
huntr MFV PoC vs LostRuins/koboldcpp otherarch/. Authorized security research (responsible disclosure via huntr).
Downloads · 30 days
0
Access
Public
Updated Jul 4, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.md2.3 KB · 45%
From the Hugging Face model README
n_dims → ne[2] stack buffer overflowhuntr MFV PoC vs LostRuins/koboldcpp otherarch/*.
Authorized security research (responsible disclosure via huntr).
koboldcpp's legacy ggml loaders read a per-tensor int32_t n_dims from the model file and loop
for (i=0;i<n_dims;++i) fin.read(&ne[i], ...) into a fixed int32_t ne[2] — with no n_dims<=2 check.
n_dims>=3 writes attacker-controlled bytes past the 2-element stack array (CWE-787). Present in gpt2_v1/
v2/v3, gptj_v1/v2/v3, mpt_v3, llama_v2/v3, neox_v2/v3, rwkv_v2 (reached via FileFormat detection).
ndims_repro.cpp / CRASH_PROVEN.md — isolated repro; EXC_BAD_ACCESS at the ne[i] store.c++ -O0 -g -fstack-protector-all ndims_repro.cpp -o ndims_repro && ./ndims_repro 100000 # -> SIGSEGV
Add if (n_dims < 0 || n_dims > 2) return ModelLoadResult::FAIL; before the ne-fill loop in each loader.