|
Download README.md from yeee3642/TensorRTDeserializeOOBPoC: direct link, hf CLI and curl.
- Browser
- Download file 917 Bytes
-
https://huggingface.co/yeee3642/TensorRTDeserializeOOBPoC/resolve/main/README.md
- Command line
-
hf download hf://yeee3642/TensorRTDeserializeOOBPoC/README.md
-
curl -L -H "Authorization: Bearer $HF_TOKEN" -o README.md https://huggingface.co/yeee3642/TensorRTDeserializeOOBPoC/resolve/main/README.md
917 Bytes
metadata
license: mit
TensorRT Deserialize OOB PoC by yee3642
This repository contains a non-weaponized proof-of-concept model file for a TensorRT plugin deserialization out-of-bounds read / denial-of-service issue.
Contents
security-poc/yee3642_poc_truncated.mytrtfile- malformed 1-byte PoC model filesecurity-poc/deserialize_value_oob_poc.cpp- local reproducer harnesssecurity-poc/make_poc_blob.py- generator for the malformed filesecurity-poc/README.md- detailed reproduction notes
Reproduction overview
- Clone the audited TensorRT source tree.
- Copy the
security-poc/directory from this repository into the TensorRT repository root. - Build the harness with
-DNDEBUGand AddressSanitizer. - Run the harness against
security-poc/yee3642_poc_truncated.mytrtfile.
Expected result: AddressSanitizer reports heap-buffer-overflow in plugin/common/serialize.hpp:58.