CVE-2024-42477

llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buffer-overflow`. This vulnerability may lead to memory data leakage. The vulnerability is fixed in b3561.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ggerganov:llama.cpp:*:*:*:*:*:*:*:*

History

15 Aug 2024, 14:02

Type Values Removed Values Added
CPE cpe:2.3:a:ggerganov:llama.cpp:*:*:*:*:*:*:*:*
Summary
  • (es) llama.cpp proporciona inferencia LLM en C/C++. El miembro "tipo" inseguro en la estructura "rpc_tensor" puede provocar un "desbordamiento de búfer global". Esta vulnerabilidad puede provocar una pérdida de datos de la memoria. La vulnerabilidad está solucionada en b3561.
First Time Ggerganov
Ggerganov llama.cpp
References () https://github.com/ggerganov/llama.cpp/commit/b72942fac998672a79a1ae3c03b340f7e629980b - () https://github.com/ggerganov/llama.cpp/commit/b72942fac998672a79a1ae3c03b340f7e629980b - Patch
References () https://github.com/ggerganov/llama.cpp/security/advisories/GHSA-mqp6-7pv6-fqjf - () https://github.com/ggerganov/llama.cpp/security/advisories/GHSA-mqp6-7pv6-fqjf - Vendor Advisory
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
CWE CWE-401

12 Aug 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-12 15:15

Updated : 2024-08-15 14:02


NVD link : CVE-2024-42477

Mitre link : CVE-2024-42477

CVE.ORG link : CVE-2024-42477


JSON object : View

Products Affected

ggerganov

  • llama.cpp
CWE
CWE-401

Missing Release of Memory after Effective Lifetime

CWE-125

Out-of-bounds Read