whisper : default-initialize whisper_mel to avoid uninitialized read (#3981)

whisper_full()/whisper_full_with_state() only compute the mel spectrogram when
n_samples > 0. For n_samples == 0 on a freshly allocated state the mel is never
touched, but struct whisper_mel had no member initializers, so n_len / n_len_org
/ n_mel were indeterminate heap garbage (the state is allocated with
new whisper_state). seek_end is derived from that garbage and, depending on it,
the call either quietly returns 0 or runs the encoder with garbage dimensions
over an empty (NULL) mel buffer, dereferencing address 0 in the mel copy loop.

Give whisper_mel default member initializers so a never-computed mel reads as
0 frames and the n_samples == 0 case deterministically takes the existing
too-short path.

Fixes #3978
This commit is contained in:
Ben Younes
2026-08-31 05:53:57 +02:00
committed by GitHub
parent c4ac0012a8
commit eacbd8234c
3 changed files with 43 additions and 3 deletions
+3 -3
View File
@@ -416,9 +416,9 @@ static const std::map<whisper_alignment_heads_preset, whisper_aheads> g_aheads {
static std::vector<uint32_t> get_alignment_heads_by_layer(const whisper_context_params & cparams, int il, int32_t n_text_layer, int32_t n_head);
struct whisper_mel {
int n_len;
int n_len_org;
int n_mel;
int n_len = 0;
int n_len_org = 0;
int n_mel = 0;
std::vector<float> data;
};