Skip to content

Validate .npy shape in mlx/io/load.cpp - #4657

Merged
zcbenz merged 2 commits into
ml-explore:mainfrom
SounLabs:fix-npy-shape-validation
Oct 9, 2026
Merged

zcbenz merged 2 commits into
ml-explore:mainfrom
SounLabs:fix-npy-shape-validation

Conversation

@SounLabs

@SounLabs SounLabs commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

A negative dimension or an overflowing product made the allocated byte count wrap to ~0 while size() stayed large, causing out-of-bounds access. Reject negative dims and use a checked multiply that throws on overflow.

Fixes #4646

  • ☑️ I understand it is strictly prohibited to use AI to write PR description
  • AI usage disclosure: it helped find the bug and draft the fix and tests. I reviewed and validated the change myself.

A negative dimension or an overflowing product made the allocated byte count wrap to ~0 while size() stayed large, causing out-of-bounds access. Reject negative dims and use a checked multiply that throws on overflow.
@zcbenz
zcbenz force-pushed the fix-npy-shape-validation branch 2 times, most recently from af0d855 to 17d85e9 Compare October 9, 2026 10:00
@zcbenz zcbenz changed the title Fix unvalidated .npy shape in mlx/io/load.cpp Validate .npy shape in mlx/io/load.cpp Oct 9, 2026
@zcbenz
zcbenz force-pushed the fix-npy-shape-validation branch from 17d85e9 to af371f8 Compare October 9, 2026 10:04
@zcbenz
zcbenz merged commit 99f109b into ml-explore:main Oct 9, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] mx.load(): unvalidated .npy shape (negative / overflowing) causes heap OOB write and read

2 participants