mirror of
https://github.com/ggml-org/whisper.cpp.git
synced 2026-10-03 13:03:07 +02:00
whisper : guard null source in buffer loader read callback (#3982)
* whisper : guard null source in buffer loader read callback whisper_init_from_buffer_with_params_no_state installs a read callback that copies from buf->buffer + current_offset. When the buffer is exhausted (or the supplied buffer is empty), size_to_copy is 0 and the source pointer can be null; passing a null pointer to memcpy is undefined behavior even for a zero-length copy (UBSan: 'null pointer passed as argument 2' at the memcpy). Loading a crafted/short model through the buffer loader could hit this. Skip the memcpy when there is nothing to copy. Loading from a null/empty or truncated buffer now fails gracefully (returns NULL) with no UB. This addresses bug 1 of #3879. Bug 2 (integer overflow when sizing the mel filter buffer) is covered by the open PR #3780. * fixup! whisper : guard null source in buffer loader read callback --------- Co-authored-by: Ben Younes <2910651+ousamabenyounes@users.noreply.github.com>
This commit is contained in:
+3
-1
@@ -3109,7 +3109,9 @@ struct parakeet_context * parakeet_init_from_buffer_with_params_no_state(void *
|
||||
|
||||
size_t size_to_copy = buf->current_offset + read_size < buf->size ? read_size : buf->size - buf->current_offset;
|
||||
|
||||
memcpy(output, buf->buffer + buf->current_offset, size_to_copy);
|
||||
if (size_to_copy > 0 && buf->buffer != nullptr) {
|
||||
memcpy(output, buf->buffer + buf->current_offset, size_to_copy);
|
||||
}
|
||||
buf->current_offset += size_to_copy;
|
||||
|
||||
return size_to_copy;
|
||||
|
||||
Reference in New Issue
Block a user