From a44e07845931421bb6f3447ce0010ed9dc76a118 Mon Sep 17 00:00:00 2001 From: Abir Deol Date: Mon, 21 Sep 2026 22:23:38 -0700 Subject: [PATCH] vad : reject n_encoder_layers other than 4 in model load (#4064) n_encoder_layers is read from the VAD model file and three channel and kernel arrays are sized to it, but the encoder graph is hardcoded to four layers and indexes those arrays at [0..3]. A value below 4 reads past the allocation, so reject anything other than 4 at the point of the read. --- src/whisper.cpp | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/whisper.cpp b/src/whisper.cpp index 4c73bbc86..771c1149c 100644 --- a/src/whisper.cpp +++ b/src/whisper.cpp @@ -4947,6 +4947,11 @@ struct whisper_vad_context * whisper_vad_init_with_params( { read_safe(loader, hparams.n_encoder_layers); + if (hparams.n_encoder_layers != 4) { + WHISPER_LOG_ERROR("%s: invalid n_encoder_layers %d in VAD model file (expected 4)\n", __func__, hparams.n_encoder_layers); + return nullptr; + } + hparams.encoder_in_channels = new int32_t[hparams.n_encoder_layers]; hparams.encoder_out_channels = new int32_t[hparams.n_encoder_layers]; hparams.kernel_sizes = new int32_t[hparams.n_encoder_layers];