Skip to content

Validate RESIZE_NEAREST_NEIGHBOR size tensor against output shape - #3680

Open
vee1e wants to merge 1 commit into
tensorflow:mainfrom
vee1e:fix-resize-nn-size-validation
Open

vee1e wants to merge 1 commit into
tensorflow:mainfrom
vee1e:fix-resize-nn-size-validation

Conversation

@vee1e

@vee1e vee1e commented Aug 25, 2026 •

Copy link
Copy Markdown

BUG=n/a

ResizeNearestNeighborPrepare() validates the size tensor's rank, type and constness but never compares its values against the declared output dimensions. Eval() then writes size[0]*size[1]*depth bytes sequentially into the output buffer, which the allocator sized from the declared shape, so a mismatch produces a linear out-of-bounds write (attacker-controlled length and content).

Reject such models at Prepare time and add a regression test that asserts a size/output mismatch fails allocation.

Verified locally: with this change, a model declaring output [1,1,1,1] with a size tensor {1024,1024} is rejected at AllocateTensors instead of overflowing the arena.

ResizeNearestNeighborPrepare() validates the size tensor's rank, type and
constness but never compares its values against the declared output dims.
Eval() then writes size[0]*size[1]*depth bytes into the output buffer, which
the allocator sized from the declared shape, so a mismatch produces a linear
out-of-bounds write.

Reject such models at Prepare time and add a regression test.
@vee1e
vee1e requested a review from a team as a code owner August 25, 2026 23:09
@vee1e

vee1e commented Aug 29, 2026

Copy link
Copy Markdown
Author

@veblush Could I have a review on this when you're free? It's a small fix that validates the size tensor.

@veblush veblush added the ci:full Triggers the comprehensive cross-platform test suite. label Sep 15, 2026
@veblush
veblush deployed to integration-test September 15, 2026 21:47 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
integration-test — 33604e7e Deployed Sep 15, 2026 by veblush via approval-gate #860
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:full Triggers the comprehensive cross-platform test suite.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants