icon

We found results for “

CVE-2024-21836

Good to know:

icon

Date: February 26, 2024

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

Language: C

Severity Score

Severity Score

Weakness Type (CWE)

Integer Overflow or Wraparound

CWE-190

Out-of-bounds Write

CWE-787

Top Fix

icon

Upgrade Version

Upgrade to version ggml-sys-bleedingedge - 2401310612.0.0+llamacpp-release.b2029;ggml-sys-bleedingedge - 2402031216.0.0+llamacpp-release.b2051;ggml-sys-bleedingedge - 2402080043.0.0+llamacpp-release.b2096;ggml-sys-bleedingedge - 2404121810.0.0+llamacpp-release.b2661;ggml-sys-bleedingedge - 2401311809.0.0+llamacpp-release.b2033;ggml-sys-bleedingedge - 2402291218.0.0+llamacpp-release.b2296;ggml-sys-bleedingedge - 2402060044.0.0+llamacpp-release.b2074;ggml-sys-bleedingedge - 2401310045.0.0+llamacpp-release.b2026;ggml-sys-bleedingedge - 2402031811.0.0+llamacpp-release.b2054;ggml-sys-bleedingedge - 2401311217.0.0+llamacpp-release.b2030;llama_cpp_rs - no_fix;whisper_cpp_sys - no_fix;llama_cpp_sys - 0.3.1;llama-cpp-sys-2 - 0.1.25;whisper-rs-sys - 0.10.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us