Repository navigation
vocab : validate special-token ids against vocab size (fix OOB read in llama_vocab::impl::load) - #25508
Closed
Yuva1l wants to merge 1 commit into
Closed
vocab : validate special-token ids against vocab size (fix OOB read in llama_vocab::impl::load)#25508Yuva1l wants to merge 1 commit into
Yuva1l wants to merge 1 commit into
Conversation
special_eos_id (and the other special-token ids) get a per-tokenizer default value. When the corresponding tokenizer.ggml.*_id KV key is absent, the default was never validated against id_to_token.size(); an out-of-range default then reaches id_to_token[tid] in the special_eog_ids loop as an out-of-bounds read. Validate each resolved id after the KV loop and disable it if it is out of range. This is the load()-path sibling of GHSA-g4cc-763q-h9h6, whose fix (c33fe8b) hardened only print_info().
Yuva1l
marked this pull request as ready for review
July 10, 2026 00:10
|
Hi @Yuva1l, thanks for your contribution! Per our contribution guidelines, the automated PR checker found the following issue(s) that need your attention:
Please note that maintainers reserve the right to make final decisions on PRs. If you believe there is a mistake, please comment below. |
Member
|
Thank you for the report. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A default special-token id can be used as an out-of-bounds index into
id_to_tokenduring vocab load, causing a heap-buffer-overflow read.This is the
load()-path sibling of GHSA-g4cc-763q-h9h6, whose fix (c33fe8b8, #14145) hardened onlyprint_info()(switching to.at()). The identical unchecked primitive remains inllama_vocab::impl::load().Root cause
Each special token gets a per-tokenizer default id (e.g.
special_eos_id = 2forllama/SPM,11forgpt2). The clamp loop inllama_vocab::impl::load()only bounds-checks an id when its KV key is present:id_to_tokenis sized ton_tokens = gguf_get_arr_n(tokenizer.ggml.tokens), which the file controls. If the file declares a tiny vocab and omits the*_idkey, the default id (e.g. 2) is never re-validated. It then flows intospecial_eog_idsand is dereferenced with a rawoperator[]in the "printing all EOG tokens" loop:Reproduce
A GGUF with a 2-token
llamavocab and notokenizer.ggml.eos_token_idkey:Fix
After resolving each special-token id (default or explicit), validate it against
id_to_token.size()and disable it (LLAMA_TOKEN_NULL) if out of range. Valid models are unaffected. With this change the PoC model loads cleanly.Impact
Out-of-bounds heap read during model load → crash (DoS) when loading an untrusted GGUF; the OOB
std::stringderef can additionally read adjacent heap. Covered scope (src/**). Severity comparable to the sibling GHSA-g4cc (Medium).