First published: Mon Feb 26 2024(Updated: )
A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
llama.cpp | ||
Llama.cpp | <2024-01-09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21802 is considered to be a critical severity vulnerability due to the potential for code execution via a specially crafted file.
To fix CVE-2024-21802, update the llama.cpp software to a version released after January 9, 2024, which addresses this vulnerability.
CVE-2024-21802 can be exploited via a specially crafted .gguf file that triggers the heap-based buffer overflow.
CVE-2024-21802 affects all versions of llama.cpp up to, but not including, version released on January 9, 2024.
Yes, the buffer overflow vulnerability in CVE-2024-21802 can potentially lead to additional vulnerabilities such as remote code execution.