SD-CPP-001: stable-diffusion.cpp GGUFReader Process Crash PoC

Security Research โ€” Responsible Disclosure

Vulnerability

Three input validation failures in src/gguf_reader.hpp (GGUFReader class) of stable-diffusion.cpp allow an attacker to crash any process loading a malformed GGUF file.

Bug Line Root Cause Impact
1 62 std::string key(key_len, '\0') with no bound check std::length_error uncaught -> std::terminate()
2 140 info.name.resize(name_len) with no bound check std::bad_alloc not caught by catch(runtime_error)
3 155 shape[3] *= shape[4] signed int64 multiply Undefined behavior (signed overflow)

Commit: d6dd6d7b555c233bb9bc9f20b4751eb8c9269743

Reproduction

python3 poc_sd_cpp_gguf_reader.py
# Generates 3 PoC files (32-92 bytes each)

# Build stable-diffusion.cpp from source
git clone https://github.com/leejet/stable-diffusion.cpp
cd stable-diffusion.cpp && mkdir build && cd build
cmake .. && cmake --build . --config Debug

# Trigger crash
./bin/sd --model /path/to/poc_metadata_oob.gguf -p "test" -o /dev/null
# Expected: "terminate called after throwing an instance of 'std::length_error'"

Trigger Condition

GGUFReader is a fallback parser invoked when gguf_init_from_file() fails (model.cpp:419). A GGUF file with version=999 triggers this fallback reliably. The fallback parser performs zero validation on length fields read from the file.

Suggested Fix

Add upper-bound validation before string allocations and widen the catch block:

// Line 62: bound key_len
if (key_len > 65536) { LOG_ERROR("key_len too large"); return false; }

// Line 214: catch all exceptions, not just runtime_error
} catch (const std::exception& e) {

Reporter

Viridis Security (Justin Hart) โ€” viridisnorthllc@gmail.com

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐Ÿ™‹ Ask for provider support