CVE-2024-23605: Integer Overflow
A heap-based buffer overflow vulnerability exists in the GGUF library header.nkv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23605?
CVE-2024-23605 is classified as a high-severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-23605?
To fix CVE-2024-23605, update the llama.cpp library to a version released after January 9, 2024.
What causes CVE-2024-23605?
CVE-2024-23605 is caused by a heap-based buffer overflow in the GGUF library's header.n_kv functionality.
What types of attacks can exploit CVE-2024-23605?
Attackers can exploit CVE-2024-23605 by providing specially crafted .gguf files to trigger the vulnerability.
Which versions of llama.cpp are affected by CVE-2024-23605?
CVE-2024-23605 affects all versions of llama.cpp up to, but not including, the version released on January 9, 2024.