First published: Mon Feb 26 2024(Updated: )
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Llama.cpp | <2024-01-09 | |
llama.cpp |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23605 is classified as a high-severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2024-23605, update the llama.cpp library to a version released after January 9, 2024.
CVE-2024-23605 is caused by a heap-based buffer overflow in the GGUF library's header.n_kv functionality.
Attackers can exploit CVE-2024-23605 by providing specially crafted .gguf files to trigger the vulnerability.
CVE-2024-23605 affects all versions of llama.cpp up to, but not including, the version released on January 9, 2024.