Database/AI/ML frameworks & serving

llama.cpp / GGUF library: Heap buffer overflow in GGUF `info
CVSS 8.8CVE-2024-21802AI/ML frameworks & servingcurated
Impact
Heap buffer overflow in GGUF info->ne parsing
Who can reach it
Customer-supplied GGUF model file
What to do
Rebuild any llama.cpp-derived binary; no host patch exists because the parser is statically linked into each tenant build
References
Related entries
- llama.cpp / GGUF: Heap overflow in `GGUF_TYPE_ARRAY`/`GGUF_TYPE_STRING` parsingCVE-2024-21825 · llama.cpp / GGUFHigh
- llama.cpp / GGUF: Heap overflow in `header.n_tensors` handlingCVE-2024-21836 · llama.cpp / GGUFHigh
- llama.cpp / GGUF: Heap overflow in `gguf_fread_str`CVE-2024-23496 · llama.cpp / GGUFHigh
- llama.cpp / GGUF: Heap overflow in `header.n_kv`CVE-2024-23605 · llama.cpp / GGUFHigh
- Ollama: Path traversal in the digest fieldCVE-2024-37032 · OllamaHigh
- MLflow (model flavors): Deserialization RCE from a maliciously uploaded model (one of a family: 37052–37060)CVE-2024-37052 · MLflow (model flavors)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.