Repository navigation
Ggml integer overflow - #29384
Ggml integer overflow#29384
Conversation
|
Hi @apach301, thanks for your contribution! Per our contribution guidelines, the automated PR checker found the following issue(s) that need your attention:
Please note that maintainers reserve the right to make final decisions on PRs. If you believe there is a mistake, please comment below. |
|
@apach301 Please address the CI failures. |
This comment was marked as low quality.
This comment was marked as low quality.
|
@ggerganov I made a fix, 2 webgpu failures seems unrelated ( |
* ggml: fix integer overflow guard for zero-element tensors * ggml: validate number of elements in tensor to prevent integer overflow * ggml: fix error print
* ggml: fix integer overflow guard for zero-element tensors * ggml: validate number of elements in tensor to prevent integer overflow * ggml: fix error print
* ggml: fix integer overflow guard for zero-element tensors * ggml: validate number of elements in tensor to prevent integer overflow * ggml: fix error print (cherry picked from commit 2149c00)
Fixes #29383
Overview
While fuzzing llama.cpp, I found several uncaught integer overflows during tensor parsing.
First one is improper int-overflow guard at gguf_init_from_reader(). The existing validation attempts
to ensure that the total number of elements is representable:
However, the arithmetic performed by the validation itself can overflow in
ggml_nelements(), before result is checked. Additionally,if one of the elements is zero (or multiplication overflows to zero), the condition becomes false and validation skipped entirely.
Another one is missing guard for possible integer overflows in ggml_new_tensor_impl(), that cause many overflow errors in ggml.c.
One of the UBSAN reports:
In both cases malformed tensor does not appear to be directly exploitable through this issue alone: subsequent checks (
check_tensor_dims, asserts) are succesfully caught errors and bail out.Additional information
Requirements