Skip to main content

PyTorch ExecuTorch

Type

Security review

Client

OSTIF

Date

2026-06

Domain

AppSec

Effort

9 wks

Section

Technology Product Reviews

Trail of Bits's security review of OSTIF (Jun 2026) identified 42 issues: 8 high, 14 medium, 19 low, and 1 undetermined.

Findings · 42

  1. 1 Null pointer dereference in get_output_flattening_encoding Low
  2. 2 Null pointer dereference in get_execution_plan Low
  3. 3 Integer overflow in tensor nbytes size computation High
  4. 4 Integer overflow in Buffer DataLoader bounds check Low
  5. 5 Stack buffer overflow in prepare_input_tensors Low
  6. 6 Abort on type mismatch in parseListOptionalType Low
  7. 7 Abort on type mismatch in Method::execute_instruction Low
  8. 8 Abort on type mismatch in parseTensorList Low
  9. 9 Out-of-bounds heap read in BPTE tensor deserialization Low
  10. 10 Out-of-bounds heap read in WAV audio file parsing Low
  11. 11 Unsafe deserialization in ETRecord parsing enables code execution High
  12. 12 Out-of-bounds heap read without InternalConsistency verification Medium
  13. 13 Out-of-bounds heap write in Program::get_constant_buffer_data High
  14. 14 Infinite loop in XNNExecutor::resize_outputs Medium
  15. 15 Out-of-bounds write in FreeCall instruction handler High
  16. 16 Out-of-bounds read in validateTensorLayout Medium
  17. 17 Integer overflow in constant segment offset validation Medium
  18. 18 Missing duplicate check in dim_order validation Medium
  19. 19 Integer overflow in tensor size validation enables heap buffer overflow Medium
  20. 20 Integer overflow in CUDA tensor copy allocation enables heap buffer overflow Medium
  21. 21 Hardcoded element size in CUDA tensor copy enables heap buffer overflow Medium
  22. 22 Integer overflow in data loader bounds checking High
  23. 23 Infinite loop with JF_CALL Low
  24. 24 Integer overflow in program file size validation Medium
  25. 25 Out-of-bounds write in Cadence HiFi bmm operator Low
  26. 26 Integer overflow in PlatformMemoryAllocator allocation High
  27. 27 Integer overflows in Vulkan tensor operations High
  28. 28 Unbounded memory allocation from untrusted PTE file Low
  29. 29 Large number of security-relevant compiler warnings Undetermined
  30. 30 Memory corruption due to unsafe mutation of FlatBuffer-backed tensor data High
  31. 31 Type confusion in BoxedEvalueList after MoveCall Medium
  32. 32 Incorrect pointer offset arithmetic in ETDumpGen constructor Low
  33. 33 Out-of-bounds read due to missing FlatBuffers verification in XNNCompiler Medium
  34. 34 Out-of-bounds read due to missing XNNHeader verification Medium
  35. 35 NULL pointer dereferences in XNNCompiler::compileModel Low
  36. 36 Crash due to unchecked map access in XNNCompiler Low
  37. 37 Unbounded memory allocation in XNNPACK subgraph creation Low
  38. 38 NULL pointer dereference in BackendDelegate::Init due to missing compile_specs validation Low
  39. 39 Heap buffer overflow in XNNPACK backend due to inconsistent tensor dimension validation Medium
  40. 40 Infinite loop in XNNPACK subgraph optimization Low
  41. 41 Out-of-bounds vector access in XNNPACK getConstantDataPtr Medium
  42. 42 Unbounded memory allocation in XNNPACK backend due to missing dimension validation Low

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related