--- license: mit tags: - security - proof-of-concept - openvino --- # OpenVINO IR `shape_size()` overflow PoC — **UNTESTED, not build-verified** This repository contains a **hand-crafted, NOT empirically verified** proof-of-concept IR model pair for a responsibly-disclosed vulnerability in [`openvinotoolkit/openvino`](https://github.com/openvinotoolkit/openvino) (tested at commit `2772fc77d9b7c8927d622a32ec782700d156203f`), reported via huntr's Model File Vulnerability program. ## Important caveat — read before using **This exact file pair was never loaded against a real, compiled OpenVINO build.** The reporter's own verification (see the full write-up submitted via huntr, and `attachments/` in this disclosure) proves the underlying arithmetic bug — the `shape_size()` integer overflow — with a standalone, compiled, and executed C++ program that copies the exact vulnerable logic from the real source, but stops short of building the full OpenVINO project (a heavy CMake-based C++ build). This XML/bin pair is a best-effort construction based on the real IR v10 schema (modeled directly on `openvino`'s own test fixture, `src/core/tests/models/ir/add_abc_initializers.xml`/`.bin`), with only the vulnerable `Const` layer's `shape` attribute changed to the exact overflow-triggering values already proven in the arithmetic PoC. **It has not been confirmed to actually load without error via `ov::Core::read_model()`** — there could be an additional consistency check elsewhere in the IR loader (e.g. between the `` attribute and the `` values, both set to the same malicious value here, or something else entirely) that rejects it before reaching the vulnerable code path, or a schema detail this reporter is unaware of. ## What these files are - `malicious_shape_overflow.xml` — an IR v10 model with a single `Const` layer whose `data` element declares `shape="4611686018427387905,4"` and `size="16"` — the exact values proven to overflow `shape_size()` down to `4` in the reporter's arithmetic PoC, making the (broken) consistency check at `xml_deserialize_util.cpp:904` pass. - `malicious_shape_overflow.bin` — 16 bytes (arbitrary content, matches the declared `size="16"`). ## How to (attempt to) reproduce ```cpp #include int main() { ov::Core core; auto model = core.read_model("malicious_shape_overflow.xml", "malicious_shape_overflow.bin"); // If loading succeeds, look for a downstream crash/OOB read when the model is used in any // operation that triggers OpenVINO's bound-propagation engine (evaluate_upper/evaluate_lower, // src/core/src/bound_evaluate.cpp) -- reached during graph construction/optimization, not // necessarily requiring actual inference. Running under AddressSanitizer is recommended to // catch the out-of-bounds read reliably. } ``` If this specific file does not reproduce the issue as-is, the reporter's arithmetic PoC (`attachments/poc_shape_size_overflow.cpp` in the main disclosure) demonstrates the exact overflow condition and can be used to adjust the `shape`/`size` values or diagnose what additional validation (if any) is blocking this particular construction. ## Scope note This PoC is provided solely for the purpose of responsible vulnerability disclosure and reproduction by the `openvino` maintainers / huntr triage team. It is not intended for any other use.