whisper : default-initialize whisper_mel to avoid uninitialized read (#3981)

whisper_full()/whisper_full_with_state() only compute the mel spectrogram when
n_samples > 0. For n_samples == 0 on a freshly allocated state the mel is never
touched, but struct whisper_mel had no member initializers, so n_len / n_len_org
/ n_mel were indeterminate heap garbage (the state is allocated with
new whisper_state). seek_end is derived from that garbage and, depending on it,
the call either quietly returns 0 or runs the encoder with garbage dimensions
over an empty (NULL) mel buffer, dereferencing address 0 in the mel copy loop.

Give whisper_mel default member initializers so a never-computed mel reads as
0 frames and the n_samples == 0 case deterministically takes the existing
too-short path.

Fixes #3978
This commit is contained in:
Ben Younes
2026-08-31 05:53:57 +02:00
committed by GitHub
parent c4ac0012a8
commit eacbd8234c
3 changed files with 43 additions and 3 deletions
+3 -3
View File
@@ -416,9 +416,9 @@ static const std::map<whisper_alignment_heads_preset, whisper_aheads> g_aheads {
static std::vector<uint32_t> get_alignment_heads_by_layer(const whisper_context_params & cparams, int il, int32_t n_text_layer, int32_t n_head);
struct whisper_mel {
int n_len;
int n_len_org;
int n_mel;
int n_len = 0;
int n_len_org = 0;
int n_mel = 0;
std::vector<float> data;
};
+10
View File
@@ -103,6 +103,16 @@ target_link_libraries(${BUFFER_LOADER_TEST} PRIVATE common)
add_test(NAME ${BUFFER_LOADER_TEST} COMMAND ${BUFFER_LOADER_TEST})
set_tests_properties(${BUFFER_LOADER_TEST} PROPERTIES LABELS "unit;gh")
# whisper_full() with n_samples == 0 must not read an uninitialized mel (#3978)
set(ZERO_SAMPLES_TEST test-whisper-zero-samples)
add_executable(${ZERO_SAMPLES_TEST} ${ZERO_SAMPLES_TEST}.cpp)
target_include_directories(${ZERO_SAMPLES_TEST} PRIVATE ../include ../ggml/include ../examples)
target_link_libraries(${ZERO_SAMPLES_TEST} PRIVATE common)
target_compile_definitions(${ZERO_SAMPLES_TEST} PRIVATE
WHISPER_MODEL_PATH="${PROJECT_SOURCE_DIR}/models/for-tests-ggml-tiny.bin")
add_test(NAME ${ZERO_SAMPLES_TEST} COMMAND ${ZERO_SAMPLES_TEST})
set_tests_properties(${ZERO_SAMPLES_TEST} PROPERTIES LABELS "tiny;gh")
# VAD test tests VAD in isolation
set(VAD_TEST test-vad)
add_executable(${VAD_TEST} ${VAD_TEST}.cpp)
+30
View File
@@ -0,0 +1,30 @@
#include "whisper.h"
#include <cstdio>
#ifdef NDEBUG
#undef NDEBUG
#endif
#include <cassert>
int main() {
struct whisper_context_params cparams = whisper_context_default_params();
cparams.use_gpu = false;
struct whisper_context * ctx = whisper_init_from_file_with_params(WHISPER_MODEL_PATH, cparams);
assert(ctx != nullptr);
struct whisper_full_params params = whisper_full_default_params(WHISPER_SAMPLING_GREEDY);
params.no_timestamps = true;
params.print_progress = false;
params.print_realtime = false;
const int rc = whisper_full(ctx, params, nullptr, 0);
assert(rc == 0);
assert(whisper_full_n_segments(ctx) == 0);
whisper_free(ctx);
printf("test-whisper-zero-samples: OK\n");
return 0;
}