摘要:
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
安全等级: Low
公告ID: KylinSec-SA-2024-2249
发布日期: 2024年5月27日
关联CVE: CVE-2024-21836
A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2024-21836 | KY3.4-4A | llama.cpp | Unaffected |
CVE-2024-21836 | KY3.4-5 | llama.cpp | Unaffected |
CVE-2024-21836 | KY3.5.1 | llama.cpp | Unaffected |
CVE-2024-21836 | KY3.5.2 | llama.cpp | Unaffected |