You need to agree to share your contact information to access this model

This repository is publicly accessible, but you have to accept the conditions to access its files and content.

Log in or Sign Up to review the conditions and access this model content.

YAML Metadata Warning:empty or missing yaml metadata in repo card

Check out the documentation for more information.

OpenVINO IR TensorIterator Port Map Validation Issue

A minimal reproduction of an input validation gap in OpenVINO's IR (Intermediate Representation) XML parser, specifically within TensorIterator and Loop layer deserialization.

Background

OpenVINO uses an XML-based format (.xml + .bin) to represent neural network models. The TensorIterator and Loop layers contain a port_map section that maps external ports to internal body subgraph ports via internal_layer_id attributes. These IDs are expected to reference Parameter (for inputs) or Result (for outputs) layers that exist within the <body> subgraph.

During deserialization (src/core/xml_util/src/xml_deserialize_util.cpp), the parser builds lookup maps (up_io_map.inputs / up_io_map.outputs) containing only the IDs of valid Parameter and Result layers found in the body. It then directly indexes these maps with internal_layer_id values read from XML attributes using std::map::at(), without first verifying that the key exists.

When a crafted model supplies an internal_layer_id that does not correspond to any Parameter or Result layer in the body, the parser throws an uncaught std::out_of_range exception, causing the loading process to abort.

Affected Code Paths

  • parse_input_description() โ€” up_io_map.inputs.at(body_parameter_index)
  • parse_output_description() โ€” up_io_map.outputs.at(body_result_index)
  • parse_purpose_attribute() โ€” up_io_map.inputs.at(...) / up_io_map.outputs.at(...)

Files in this Repository

File Description
poc_ti_invariant.xml Triggers the invariant input path (no axis attribute)
poc_ti_sliced.xml Triggers the sliced input path (with axis attribute)
poc_ti_output.xml Triggers the output description path
poc_loop.xml Triggers the Loop purpose attribute path
reproduce.py Automated reproduction script

Reproduction

Prerequisites

pip install openvino

Run

python reproduce.py

Expected output for the invariant input path:

OpenVINO 2026.2.1-...
Devices: ['CPU']

[TEST] TensorIterator invariant input path
  Loading poc_ti_invariant.xml...
  Caught RuntimeError: Exception from src/inference/src/cpp/core.cpp:84:
  Check 'false' failed at src/frontends/common/src/frontend.cpp:53:
  Converting input model
  unordered_map::at

  => Parser aborts on non-existent internal_layer_id

Root Cause

The internal_layer_id attribute in port_map entries is attacker-controlled XML data. The deserialization code assumes it always references a valid body layer, but never validates this assumption before the std::map::at() lookup.

Impact

Any application or service that loads untrusted OpenVINO IR models (e.g., model inference servers, CI/CD validation pipelines, model marketplaces) can be caused to abort by supplying a malformed .xml file.

No .bin weights file is required โ€” the crash occurs during pure XML topology parsing.

Tested Versions

  • openvino==2026.2.1-21919-ede283a88e3-releases/2026/2 (PyPI)

Suggested Fix

Replace unchecked map.at(key) calls with map.find(key) + iterator validation:

auto it = up_io_map.inputs.find(body_parameter_index);
if (it == up_io_map.inputs.end()) {
    OPENVINO_THROW("Invalid internal_layer_id: ", body_parameter_index,
                   " not found in body parameters");
}
const auto input_index = it->second;
Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐Ÿ™‹ Ask for provider support