onnxruntime
e5f272c9 - Fix OOB read in InferenceContextImpl::getInputData (#32681)

Commit
5 days ago
Fix OOB read in InferenceContextImpl::getInputData (#32681) ### Description `InferenceContextImpl::getInputData` (graph.cc) indexed `node_.InputDefs()` directly by the schema input index during shape inference, with no bounds check. Add the same bounds check already used by `DataPropagationContextImpl::getInputData` in the same file, so `getInputData` returns `nullptr` (treated as "input not available") instead of indexing out of bounds. ### Motivation and Context ONNX schemas can declare trailing inputs as optional (e.g. `ConvTransposeWithDynamicPads`'s `Pads`), so a node can validly omit them entirely, shrinking `Node::InputDefs()` below the schema's full input count. A `TypeAndShapeInferenceFunction` that queries such an omitted optional input's data (e.g. via `ctx.getInputData(index)`) on such a node reads past the end of the vector, causing an out-of-bounds read.
Author
Parents
Loading