Vulnerability Disclosure: Critical ACE in TensorRT Parser

Vulnerability

Arbitrary Code Execution (ACE) via malformed TensorRT engine header.

Description

The TensorRT engine parser fails to validate the size prefix for internal data structures, leading to a heap-based buffer overflow when processing a maliciously crafted engine file.

Proof of Concept

The provided poc_trt.engine triggers a memory corruption event during the deserialization phase.

Steps to Reproduce

  1. Attempt to load the model using tensorrt library.
  2. Observe segmentation fault or memory corruption.

Recommendation

Implement rigorous size validation for all engine header segments.

Downloads last month
-
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support