whisper : guard null source in buffer loader read callback (#3982)

* whisper : guard null source in buffer loader read callback

whisper_init_from_buffer_with_params_no_state installs a read callback that
copies from buf->buffer + current_offset. When the buffer is exhausted (or the
supplied buffer is empty), size_to_copy is 0 and the source pointer can be null;
passing a null pointer to memcpy is undefined behavior even for a zero-length
copy (UBSan: 'null pointer passed as argument 2' at the memcpy). Loading a
crafted/short model through the buffer loader could hit this.

Skip the memcpy when there is nothing to copy. Loading from a null/empty or
truncated buffer now fails gracefully (returns NULL) with no UB.

This addresses bug 1 of #3879. Bug 2 (integer overflow when sizing the mel
filter buffer) is covered by the open PR #3780.

* fixup! whisper : guard null source in buffer loader read callback

---------

Co-authored-by: Ben Younes <2910651+ousamabenyounes@users.noreply.github.com>
This commit is contained in:
Ben Younes
2026-08-25 12:40:19 +02:00
committed by GitHub
co-authored by Ben Younes
parent c122757fdd
commit a722846cb6
4 changed files with 37 additions and 3 deletions
+7 -1
View File
@@ -96,6 +96,13 @@ target_link_libraries(${UTF8_TEST} PRIVATE common)
add_test(NAME ${UTF8_TEST} COMMAND ${UTF8_TEST})
set_tests_properties(${UTF8_TEST} PROPERTIES LABELS "unit")
set(BUFFER_LOADER_TEST test-whisper-buffer-loader)
add_executable(${BUFFER_LOADER_TEST} ${BUFFER_LOADER_TEST}.cpp)
target_include_directories(${BUFFER_LOADER_TEST} PRIVATE ../include ../ggml/include ../examples)
target_link_libraries(${BUFFER_LOADER_TEST} PRIVATE common)
add_test(NAME ${BUFFER_LOADER_TEST} COMMAND ${BUFFER_LOADER_TEST})
set_tests_properties(${BUFFER_LOADER_TEST} PROPERTIES LABELS "unit;gh")
# VAD test tests VAD in isolation
set(VAD_TEST test-vad)
add_executable(${VAD_TEST} ${VAD_TEST}.cpp)
@@ -177,4 +184,3 @@ add_parakeet_transcription_test(
samples/diffusion2023-07-03.flac
tests/parakeet-expected-diffusion-output.txt
0.95)
+24
View File
@@ -0,0 +1,24 @@
#include "whisper.h"
#include <cstdint>
#include <cstdio>
#ifdef NDEBUG
#undef NDEBUG
#endif
#include <cassert>
int main() {
struct whisper_context_params cparams = whisper_context_default_params();
cparams.use_gpu = false;
struct whisper_context * ctx_empty = whisper_init_from_buffer_with_params(nullptr, 1, cparams);
assert(ctx_empty == nullptr);
uint8_t truncated[8] = { 0 };
struct whisper_context * ctx_trunc = whisper_init_from_buffer_with_params(truncated, sizeof(truncated), cparams);
assert(ctx_trunc == nullptr);
printf("test-whisper-buffer-loader: OK\n");
return 0;
}