Tensorizer uninitialized-memory-disclosure PoC

This repository contains a proof-of-concept .tensors file for a responsibly-disclosed vulnerability in coreweave/tensorizer (tested at commit 652d3c016c84836bba97153e108821c11428ac40, version 2.12.1), reported via huntr's Model File Vulnerability program.

What this file is

malicious.tensors is a syntactically valid Tensorizer file whose header/metadata index declares one tensor (poc_tensor, 200,000 bytes of float32 data), but whose data section has been truncated to only 50,000 real bytes. The declared data_length for the tensor is left unchanged.

What happens when you load it

from tensorizer import TensorDeserializer

d = TensorDeserializer("malicious.tensors", verify_hash=False, lazy_load=False)
t = d["poc_tensor"]  # succeeds -- no exception is raised

TensorDeserializer allocates the tensor's backing buffer with torch.empty(...) (uninitialized memory) sized to the declared data_length, reads however many bytes are actually available from the stream via readinto(), and never checks that the number of bytes read matches what was requested. The 150,000 bytes that were never physically present in the file are left as whatever was already sitting in that memory region of the host process — not zeroed, not an error.

Depending on what the host process had recently allocated, this can expose residual heap contents (other in-process data) as if it were part of the loaded tensor's legitimate weights, with no indication to the caller that anything is wrong.

See the reporter's full write-up submitted via huntr for the complete technical analysis, including a reproduction that deliberately "dirties" the process heap with a recognizable byte pattern beforehand and shows that pattern reappearing verbatim in the loaded tensor's data.

Scope note

This PoC is provided solely for the purpose of responsible vulnerability disclosure and reproduction by the tensorizer maintainers / huntr triage team. It is not intended for any other use.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support