CNTK ReadName() Integer Overflow PoC
Bug
BinaryDataDeserializer.h:85: len + 1 overflows to 0 when len = 0xFFFFFFFF.
Creates 0-byte buffer, then reads ~4GB into it โ heap buffer overflow.
File
readname_overflow.bin โ Binary with name length = 0xFFFFFFFF
Reproduce
Build CNTK with ASan, load the binary file as a data reader input.
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐ Ask for provider support