PT-2024-2168 · Unknown · Gguf Library

Francesco Benvenuto

·

Published

2024-02-26

·

Updated

2026-04-27

·

CVE-2024-23496

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GGUF library version Commit 18c2e17
Description A heap-based buffer overflow vulnerability exists in the GGUF library gguf fread str functionality of llama.cpp. This vulnerability can be triggered by a specially crafted .gguf file, potentially leading to code execution. An attacker can exploit this issue by providing a malicious file.
Recommendations As a temporary workaround, consider disabling the gguf fread str function until a patch is available. Restrict access to the vulnerable llama.cpp module to minimize the risk of exploitation. Avoid using the GGUF library until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Memory Corruption

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-02082
CVE-2024-23496

Affected Products

Gguf Library