Views
No views yet
artifacts/underflow_appends.pt is a minimal TorchScript ZIP archive with a malformed constants.pkl payload:180 02 5d 65 2e
2PROTO 2, EMPTY_LIST, APPENDS, STOP1.4.0, torch.jit.load() reaches the JIT unpickler and crashes natively on this malformed pickle opcode sequence. Current PyTorch versions tested locally return clean parser errors instead, so this report is specifically scoped to TorchScript v1.4.1.4.0 installed:python verify_torchscript_v14_dos.py --python /path/to/python-with-torch-1.4.01{
2 "returncode": -11,
3 "native_crash": true
4}139; SIGABRT variants appear as 134.torch.jit.load() on the artifact. This is a model-file-carried denial of service. It is not arbitrary code execution and no controlled memory-corruption primitive is claimed.evidence/torch_1_4_matrix.txt: PyTorch 1.4.0 crash matrix for malformed constants.pkl variants.evidence/current_torch_2_8_matrix_nomemlimit.txt: current-version comparison showing clean parser errors.evidence/modelscan_0_8_8_underflow_appends.json: ModelScan 0.8.8 output, zero issues while scanning ts/constants.pkl.bd34cabfd35feb96ced8a63489c5899aa9b17c000ce552406519998d5d3855f1 artifacts/underflow_appends.pt