Tensorizer uninitialized-memory-disclosure PoC
This repository contains a proof-of-concept .tensors file for a responsibly-disclosed
vulnerability in coreweave/tensorizer (tested at
commit 652d3c016c84836bba97153e108821c11428ac40, version 2.12.1), reported via huntr's
Model File Vulnerability program.
What this file is
malicious.tensors is a syntactically valid Tensorizer file whose header/metadata index declares
one tensor (poc_tensor, 200,000 bytes of float32 data), but whose data section has been
truncated to only 50,000 real bytes. The declared data_length for the tensor is left unchanged.
What happens when you load it
from tensorizer import TensorDeserializer
d = TensorDeserializer("malicious.tensors", verify_hash=False, lazy_load=False)
t = d["poc_tensor"] # succeeds -- no exception is raised
TensorDeserializer allocates the tensor's backing buffer with torch.empty(...) (uninitialized
memory) sized to the declared data_length, reads however many bytes are actually available
from the stream via readinto(), and never checks that the number of bytes read matches what was
requested. The 150,000 bytes that were never physically present in the file are left as whatever
was already sitting in that memory region of the host process — not zeroed, not an error.
Depending on what the host process had recently allocated, this can expose residual heap contents (other in-process data) as if it were part of the loaded tensor's legitimate weights, with no indication to the caller that anything is wrong.
See the reporter's full write-up submitted via huntr for the complete technical analysis, including a reproduction that deliberately "dirties" the process heap with a recognizable byte pattern beforehand and shows that pattern reappearing verbatim in the loaded tensor's data.
Scope note
This PoC is provided solely for the purpose of responsible vulnerability disclosure and
reproduction by the tensorizer maintainers / huntr triage team. It is not intended for any other
use.