SD-CPP-001: stable-diffusion.cpp GGUFReader Process Crash PoC
Security Research โ Responsible Disclosure
Vulnerability
Three input validation failures in src/gguf_reader.hpp (GGUFReader class) of stable-diffusion.cpp allow an attacker to crash any process loading a malformed GGUF file.
| Bug | Line | Root Cause | Impact |
|---|---|---|---|
| 1 | 62 | std::string key(key_len, '\0') with no bound check |
std::length_error uncaught -> std::terminate() |
| 2 | 140 | info.name.resize(name_len) with no bound check |
std::bad_alloc not caught by catch(runtime_error) |
| 3 | 155 | shape[3] *= shape[4] signed int64 multiply |
Undefined behavior (signed overflow) |
Commit: d6dd6d7b555c233bb9bc9f20b4751eb8c9269743
Reproduction
python3 poc_sd_cpp_gguf_reader.py
# Generates 3 PoC files (32-92 bytes each)
# Build stable-diffusion.cpp from source
git clone https://github.com/leejet/stable-diffusion.cpp
cd stable-diffusion.cpp && mkdir build && cd build
cmake .. && cmake --build . --config Debug
# Trigger crash
./bin/sd --model /path/to/poc_metadata_oob.gguf -p "test" -o /dev/null
# Expected: "terminate called after throwing an instance of 'std::length_error'"
Trigger Condition
GGUFReader is a fallback parser invoked when gguf_init_from_file() fails (model.cpp:419). A GGUF file with version=999 triggers this fallback reliably. The fallback parser performs zero validation on length fields read from the file.
Suggested Fix
Add upper-bound validation before string allocations and widen the catch block:
// Line 62: bound key_len
if (key_len > 65536) { LOG_ERROR("key_len too large"); return false; }
// Line 214: catch all exceptions, not just runtime_error
} catch (const std::exception& e) {
Reporter
Viridis Security (Justin Hart) โ viridisnorthllc@gmail.com
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐ Ask for provider support