Commit b5f35d4
Fix integer overflows in tensor byte-size computations (pytorch#19055)
Three tensor-byte-size multiplications had no overflow check, letting a
malicious PTE trigger wrap-to-small size_t values while kernels iterate
on the un-wrapped element count, producing heap buffer overflows.
Fixed here:
- extension/tensor/tensor_ptr.h: data.size() * elementSize(type) in
make_tensor_ptr cast path.
- extension/tensor/tensor_ptr_maker.cpp: compute_numel(...) *
elementSize(type) in empty_strided.
- runtime/core/tensor_layout.cpp: dim-product loop and final *
elementSize(scalar_type) in calculate_nbytes; now returns
Error::InvalidArgument on overflow since the function already returns
Result<size_t>.
All guards use c10::mul_overflows, matching the existing pattern in
MethodMeta::calculate_nbytes, the data loaders, and
PlatformMemoryAllocator.
runtime/core/portable_type/tensor_impl.cpp is intentionally left alone
in this branch; guarding the nbytes() / compute_numel multiplications
there breaks internal callers and will be handled separately.
Authored with Claude.1 parent 2a0a564 commit b5f35d4
3 files changed
Lines changed: 38 additions & 7 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| 17 | + | |
17 | 18 | | |
18 | 19 | | |
19 | 20 | | |
| |||
117 | 118 | | |
118 | 119 | | |
119 | 120 | | |
120 | | - | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
121 | 131 | | |
122 | 132 | | |
123 | 133 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
| 14 | + | |
13 | 15 | | |
14 | 16 | | |
15 | 17 | | |
| |||
111 | 113 | | |
112 | 114 | | |
113 | 115 | | |
114 | | - | |
115 | | - | |
116 | | - | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
117 | 127 | | |
118 | 128 | | |
119 | 129 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
10 | 11 | | |
11 | 12 | | |
12 | 13 | | |
| |||
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
22 | | - | |
| 23 | + | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
26 | 27 | | |
27 | | - | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
28 | 33 | | |
29 | 34 | | |
30 | | - | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
31 | 42 | | |
32 | 43 | | |
33 | 44 | | |
| |||
0 commit comments