From db7cfae2565eb962d72730838053c237705c4407 Mon Sep 17 00:00:00 2001 From: Ashutosh0x Date: Thu, 28 May 2026 23:41:34 +0530 Subject: [PATCH] gguf: fix division by zero in tensor dimension validation A crafted GGUF file with ne[1]=0, ne[2]=0, or ne[3]=0 causes a division by zero (SIGFPE) at the overflow check: INT64_MAX/info.t.ne[1] <= info.t.ne[0] The existing validation only rejects negative dimensions (ne < 0), but ne == 0 passes through and reaches the division. This crashes the process unconditionally - no resource exhaustion, no graceful error handling, just an immediate SIGFPE. A 73-byte crafted file is sufficient to trigger the crash. Fix: change the validation from ne < 0 to ne <= 0. A tensor dimension of zero is invalid in GGUF model files. --- src/gguf.cpp | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/src/gguf.cpp b/src/gguf.cpp index 5e19861825..ec2c8edc05 100644 --- a/src/gguf.cpp +++ b/src/gguf.cpp @@ -668,9 +668,10 @@ static struct gguf_context * gguf_init_from_reader(const struct gguf_reader & gr ok = ok && gr.read(info.t.ne[j]); } - // check that all ne are non-negative - if (info.t.ne[j] < 0) { - GGML_LOG_ERROR("%s: tensor '%s' dimension %" PRIu32 " has invalid number of elements: %" PRIi64 " < 0\n", + // check that all ne are positive (ne == 0 causes division by zero + // in the overflow check below: INT64_MAX/ne[1], INT64_MAX/ne[2], etc.) + if (info.t.ne[j] <= 0) { + GGML_LOG_ERROR("%s: tensor '%s' dimension %" PRIu32 " has invalid number of elements: %" PRIi64 " <= 0\n", __func__, info.t.name, j, info.t.ne[j]); ok = false; break;