Skip to content

Fix OOB read in InferenceContextImpl::getInputData - #32681

Merged
adrastogi merged 2 commits into
microsoft:mainfrom
bbernhar:fix_58
Sep 23, 2026
Merged

adrastogi merged 2 commits into
microsoft:mainfrom
bbernhar:fix_58

Conversation

@bbernhar

@bbernhar Bryan B (bbernhar) commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Description

InferenceContextImpl::getInputData (graph.cc) indexed node_.InputDefs() directly by
the schema input index during shape inference, with no bounds check. Add the same bounds
check already used by DataPropagationContextImpl::getInputData in the same file, so
getInputData returns nullptr (treated as "input not available") instead of indexing
out of bounds.

Motivation and Context

ONNX schemas can declare trailing inputs as optional (e.g. ConvTransposeWithDynamicPads's
Pads), so a node can validly omit them entirely, shrinking Node::InputDefs() below the
schema's full input count. A TypeAndShapeInferenceFunction that queries such an omitted
optional input's data (e.g. via ctx.getInputData(index)) on such a node reads past the
end of the vector, causing an out-of-bounds read.

Copilot AI balanced review requested due to automatic review settings September 17, 2026 17:47
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new tests exercise unfixed out-of-bounds paths, while the stated omitted-pads regression remains untested.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Prevents crashes when ConvTransposeWithDynamicPads omits its optional Pads input.

Changes:

  • Bounds-checks shape-inference input data access.
  • Rejects missing dynamic pads during CPU execution.
  • Adds mismatched-rank regression tests.
File summaries
File Description
onnxruntime/core/graph/graph.cc Guards omitted input access.
onnxruntime/core/providers/cpu/nn/conv_transpose_attributes.h Handles null dynamic pads.
onnxruntime/test/contrib_ops/conv_transpose_with_dynamic_pads_test.cc Adds rank-mismatch tests.
Review details

Suppressed comments (1)

onnxruntime/test/contrib_ops/conv_transpose_with_dynamic_pads_test.cc:92

  • This case also exercises an out-of-bounds access that is not fixed by this PR. With one input spatial dimension and three weight spatial dimensions, shape inference creates a one-element dilations vector and then indexes it three times while scaling kernel_shape (contrib_defs.cc:113-117). The expected kernel error is reached only after undefined behavior. Add the same X/W rank-equality validation in shape inference before this loop.
TEST(ContribOpTest, ConvTransposeWithDynamicPads_LongerWeightRank) {
  OpTester test("ConvTransposeWithDynamicPads", 1, onnxruntime::kMSDomain);
  test.AddInput<float>("X", {1, 1, 2}, std::vector<float>(2, 0.0f));
  test.AddInput<float>("W", {1, 1, 3, 3, 3}, std::vector<float>(27, 0.0f));
  test.AddInput<int64_t>("Pads", {2}, std::vector<int64_t>(2, 0));
  • Files reviewed: 3/3 changed files
  • Comments generated: 2
  • Review effort level: Balanced (auto)

Note

Copilot is running an experiment and ran this review at Balanced.


💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread onnxruntime/test/contrib_ops/conv_transpose_with_dynamic_pads_test.cc Outdated
Comment thread onnxruntime/core/providers/cpu/nn/conv_transpose_attributes.h Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The missing-pads test expects a CPU-specific error and will fail under the cuDNN 9 CUDA provider.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 1
  • Review effort level: Balanced (auto)

Note

Copilot is running an experiment and ran this review at Balanced.

Comment thread onnxruntime/test/contrib_ops/conv_transpose_with_dynamic_pads_test.cc Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The cuDNN 8 cached execution path can bypass the new validation on a repeated run.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 1
  • Review effort level: Balanced (auto)

Note

Copilot is running an experiment and ran this review at Balanced.

Comment thread onnxruntime/core/providers/cpu/nn/conv_transpose_attributes.h Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

CUDA 8 can reuse an algorithm and workspace cached for a different dynamic-padding descriptor, and the repeated-run path lacks coverage.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 2
  • Review effort level: Balanced

Comment thread onnxruntime/core/providers/cuda/nn/conv_transpose_8.h Outdated
Comment thread onnxruntime/test/contrib_ops/conv_transpose_with_dynamic_pads_test.cc Outdated
@bbernhar
Bryan B (bbernhar) force-pushed the fix_58 branch 2 times, most recently from bae0a22 to 8071b1c Compare September 17, 2026 20:46
@bbernhar Bryan B (bbernhar) changed the title Fix OOB read and null-deref in ConvTransposeWithDynamicPads Fix OOB read in InferenceContextImpl::getInputData Sep 17, 2026
@bbernhar
Bryan B (bbernhar) requested a balanced review from Copilot September 17, 2026 20:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The memory-safety fix needs a regression test covering an omitted trailing input.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Balanced (auto)

Note

Copilot is running an experiment and ran this review at Balanced.

Comment thread onnxruntime/core/graph/graph.cc
optional input is omitted

'Pads' on ConvTransposeWithDynamicPads is schema-optional, so a node can
validly supply only [X, W]. InferenceContextImpl::getInputData (graph.cc)
indexed node_.InputDefs() by the ONNX input index without checking it
against InputDefs().size(), so shape inference on such a node read past
the end of the vector. Add the same bounds check already used by
DataPropagationContextImpl::getInputData.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused bounds check matches existing behavior and the regression test covers the reported failure path.

Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced (auto)

Note

Copilot is running an experiment and ran this review at Balanced.

@xadupre

Copy link
Copy Markdown
Member

The failing build is fixed in main branch.

@bbernhar

Copy link
Copy Markdown
Contributor Author

Xavier Dupré (@xadupre) merged main

@adrastogi
adrastogi merged commit e5f272c into microsoft:main Sep 23, 2026
90 of 91 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants