Skip to content

Security Vulnerability: Integer overflow in ElementCount() leads to heap buffer overflow #3761

Description

@0xanubiis

#Hi maintainers,

I reported this to Google's VRP. They instructed me to report it directly upstream and said if you recognize it as a security vulnerability, I can reopen my report.

My original PR (#3658) was closed with the reason: "This type change will not be implemented prior to the upstream LiteRT adopting such changes."

I have audited the LiteRT repository and confirmed that the vulnerable ElementCount() function does not exist there. It is specific to tflite-micro.

Because that reason no longer applies, I am asking you to please formally acknowledge:

  1. Is this a security vulnerability in tflite-micro?
  2. If yes, can you provide a statement so I can reopen my report with Google's VRP?
  3. If no, please explain why it is not considered a vulnerability.

Evidence:

  • UBSan: signed integer overflow
  • ASan: SEGV crash
  • LiteRT scan: no vulnerable ElementCount()

Thank you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions