CVE-2024-23605

Name
CVE-2024-23605
Description
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
talos-cna@cisco.com https://talosintelligence.com/vulnerability_reports/TALOS-2024-1916
talos-cna@cisco.com https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1916

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ggerganov:llama.cpp:*:*:*:*:*:*:*:* llama.cpp >= None < 2024-01-09

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
llama.cpp edge-community 0.0.9564-r0 Hugo Osvaldo Barrera <hugo@whynothugo.nl> possibly vulnerable
llama.cpp edge-community 0.0.9006-r0 Hugo Osvaldo Barrera <hugo@whynothugo.nl> possibly vulnerable