漏洞入口点是 torch/serialization.py 中的 load() 函数
当保护(weights_only)启用时: 加载 tar 文件会依次调用以下函数:
load(): torch/serialization.py:1117_load_legacy(): torch/serialization.py:1376 至 torch/serialization.py:1406persistent_load(): torch/serialization.py:1474pickle_module.load(): torch/serialization.py:1487Unpickler.load(): torch/_weights_only_unpickler.py:214在 weights_only_unpickler 模式下,整个过程围绕 pickle 反序列化展开,因此搜索 pickle 协议可能会有所帮助。 参考:https://rushter.com/blog/pickle-serialization-internals/
本 POC 首先生成一个恶意 tar 文件,注意文件名 “storages” 是 pytorch 所必需的,然后加载该 tar 文件以触发漏洞。
目前该 tar 文件在不安全模式下是可执行的。下一步是启用安全保护并绕过验证,例如:
_pickle.UnpicklingError: Unsupported global: GLOBAL __builtin__.eval was not an allowed global by default. Please use `torch.serialization.add_safe_globals([eval])` to allowlist this global if you trust this class/function.