Skip to content

fix(hnswalg): reject loadIndex when max_elements_ < cur_element_count - #677

Open
chakshu-dhannawat wants to merge 1 commit into
nmslib:masterfrom
chakshu-dhannawat:fix/loadindex-max-elements-bound-check
Open

chakshu-dhannawat wants to merge 1 commit into
nmslib:masterfrom
chakshu-dhannawat:fix/loadindex-max-elements-bound-check

Conversation

@chakshu-dhannawat

@chakshu-dhannawat chakshu-dhannawat commented Sep 7, 2026 •

Copy link
Copy Markdown

Fixes #673

loadIndex sized the level-0 allocation from the file's max_elements_ field but then read cur_element_count * size_data_per_element_ bytes. A crafted index with max_elements_ < cur_element_count therefore caused a heap-buffer-overflow write.

Add a bound check right after max_elements_ is finalized so malformed indexes throw Index seems to be corrupted or unsupported instead of overflowing.

Added tests/python/bindings_test_loadindex_corruption.py with two tests: one that crafts a malformed 2-element index with max_elements_=1 and asserts loading raises RuntimeError, and one that verifies a normal saved index still loads and self-searches correctly.

All Python binding tests pass (16/16).

ilyajob05 added a commit that referenced this pull request Sep 13, 2026
getDataByLabelNoExceptions: construct the vector from [ptr, ptr+dim)
instead of a push_back loop (#679).

loadIndexNoExceptions: if the file's max_elements_ is smaller than
cur_element_count, return Status instead of allocating a short buffer
(#677, adapted from throw to Status for the no-exceptions API).

Co-authored-by: ronak singh <singhronak2008@gmail.com>
Co-authored-by: Chakshu Dhannawat <chakshu.dhannawat1@gmail.com>
ilyajob05 added a commit to ilyajob05/hnswlib that referenced this pull request Sep 14, 2026
getDataByLabelNoExceptions: construct the vector from [ptr, ptr+dim)
instead of a push_back loop (nmslib#679).

loadIndexNoExceptions: if the file's max_elements_ is smaller than
cur_element_count, return Status instead of allocating a short buffer
(nmslib#677, adapted from throw to Status for the no-exceptions API).

Co-authored-by: ronak singh <singhronak2008@gmail.com>
Co-authored-by: Chakshu Dhannawat <chakshu.dhannawat1@gmail.com>
@chakshu-dhannawat
chakshu-dhannawat force-pushed the fix/loadindex-max-elements-bound-check branch from 529810b to b3f1fcc Compare September 24, 2026 00:31
@chakshu-dhannawat
chakshu-dhannawat force-pushed the fix/loadindex-max-elements-bound-check branch from b3f1fcc to 280cb59 Compare September 24, 2026 01:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Heap-buffer-overflow WRITE in loadIndex() via mismatched max_elements_/cur_element_count (crafted index file)

1 participant