Skip to content

Reject AdditiveQuantizer with zero-bit code size on deserialization - #5506

Closed
juancarpio27 wants to merge 1 commit into
facebookresearch:mainfrom
juancarpio27:export-D115173394
Closed

Reject AdditiveQuantizer with zero-bit code size on deserialization#5506
juancarpio27 wants to merge 1 commit into
facebookresearch:mainfrom
juancarpio27:export-D115173394

Conversation

@juancarpio27

Copy link
Copy Markdown

Summary:
Deserializing an AdditiveQuantizer-based index (residual quantizer,
local-search quantizer, and their product variants) validated that the
number of sub-quantizers M is positive, but not that the resulting
per-vector code size is nonzero. A crafted index can set every
sub-quantizer's bit width to 0, which makes the derived code size 0
while the index still declares a positive vector count.

Such an index ends up with an empty codes buffer whose data pointer is
null/unspecified. Decoding any vector then dereferences that pointer
inside the bitstring reader used to unpack per-vector codes, causing a
segfault on fully attacker-controlled input.

Reject this configuration right where the code size is derived, with a
descriptive exception. A quantizer that stores zero bits per vector
cannot decode anything and is never produced by real training, so this
only rejects malformed/crafted inputs.

Differential Revision: D115173394

Summary:
Deserializing an AdditiveQuantizer-based index (residual quantizer,
local-search quantizer, and their product variants) validated that the
number of sub-quantizers M is positive, but not that the resulting
per-vector code size is nonzero. A crafted index can set every
sub-quantizer's bit width to 0, which makes the derived code size 0
while the index still declares a positive vector count.

Such an index ends up with an empty codes buffer whose data pointer is
null/unspecified. Decoding any vector then dereferences that pointer
inside the bitstring reader used to unpack per-vector codes, causing a
segfault on fully attacker-controlled input.

Reject this configuration right where the code size is derived, with a
descriptive exception. A quantizer that stores zero bits per vector
cannot decode anything and is never produced by real training, so this
only rejects malformed/crafted inputs.

Differential Revision: D115173394
@meta-cla meta-cla Bot added the CLA Signed label Aug 7, 2026
@meta-codesync

meta-codesync Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

@juancarpio27 has exported this pull request. If you are a Meta employee, you can view the originating Diff in D115173394.

@meta-codesync

meta-codesync Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

This pull request has been merged in a9ecee2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant