Skip to content

vad : reject n_encoder_layers other than 4 in model load - #4064

Merged
danbev merged 1 commit into
ggml-org:masterfrom
apollo-2006:vad-reject-invalid-encoder-layers
Sep 22, 2026
Merged

danbev merged 1 commit into
ggml-org:masterfrom
apollo-2006:vad-reject-invalid-encoder-layers

Conversation

@apollo-2006

@apollo-2006 apollo-2006 commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

A VAD model whose header declares n_encoder_layers other than 4 causes an out-of-bounds heap read in whisper_vad_init_with_params, reachable from the ordinary whisper-cli --vad -vm <file> path on any user-supplied VAD model.

n_encoder_layers is read from the file and used, unbounded, to size three heap arrays, while the encoder graph below is hardcoded to four layers and indexes those arrays at [0..3] regardless of what the file declared. A value below 4 reads past the allocation.

The fix rejects it at the point of the read, matching the n_dims guard in #3957. The graph only implements four layers, so any other value is out of range rather than something to accommodate. For a well-formed model this is a no-op.

Tested with a crafted 3-layer model: SIGABRT before, rejected with exit 10 after, and heap-buffer-overflow under ASan before, clean after. The real silero v6.2.0 model transcribes unchanged. test-vad and test-vad-full pass.

Copilot AI lite review requested due to automatic review settings September 13, 2026 02:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Comment thread src/whisper.cpp Outdated
n_encoder_layers is read from the VAD model file and three channel and
kernel arrays are sized to it, but the encoder graph is hardcoded to four
layers and indexes those arrays at [0..3]. A value below 4 reads past the
allocation, so reject anything other than 4 at the point of the read.
@apollo-2006
apollo-2006 force-pushed the vad-reject-invalid-encoder-layers branch from a894528 to 987cad1 Compare September 21, 2026 15:23
@apollo-2006

Copy link
Copy Markdown
Contributor Author

comments are gone, and ive trimmed the description. thank you for the review. sorry for the inconvenience

@danbev
danbev merged commit a44e078 into ggml-org:master Sep 22, 2026
45 of 47 checks passed
bygreencn added a commit to bygreencn/whisper.cpp that referenced this pull request Sep 23, 2026
* ggerganov/master:
  vad : reject n_encoder_layers other than 4 in model load (ggml-org#4064)
  devops : reduce Vulkan Docker image to 39.4% of its original size (now 692 MB) (ggml-org#4038)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants