Database/AI/ML frameworks & serving
mistral.rs: out-of-bounds read parsing GGUF token id metadata crashes the inference server
Impact
Token id fields in a GGUF file (eos_token_id, bos_token_id, unknown_token_id) are used without bounds checking when converting the GGUF tokenizer to the HF format, giving an out-of-bounds read. Anyone who can get the server to load a crafted GGUF model takes down the serving process; on a GPU node that means the model has to be reloaded and warmed again, and the GPU sits idle through it. The record claims availability impact only - no confidentiality or integrity - and exploit details are public. Operators who let users supply their own model weights carry the real exposure here.
Who can reach it
Anyone who can place a GGUF file the server will load - a self-serve model upload path, a shared model cache, or a hub pull of an untrusted repo. No authentication is implied by the record, but the CVSS vector marks user interaction as required, i.e. someone must load the model.
What to do
Upgrade to mistral.rs 0.8.23 (patch cd5297e) and restart the inference process; each model must be reloaded onto the GPU afterwards. Until patched, only load GGUF files from sources you control and keep tenant-supplied weights out of shared serving instances.
References
Related entries
- Ollama: integer overflow in the GGUF v1 string reader when parsing a crafted model fileCVE-2026-86289 · Ollama GGUF decoder (readGGUFV1String in fs/ggml/gguf.go)Low
- vLLM: attacker-supplied chat_template burns server resources on the GPU nodeCVE-2026-90878 · vLLM OpenAI-compatible server (/v1/chat/completions Jinja chat_template rendering)Low
- vLLM: malformed tiktoken vocab file crashes the tokenizer backend, denying service on the GPU nodeCVE-2026-90713 · vLLM (Rust tiktoken vocab file handler, TiktokenTokenizer::new)Low
- LangChain4j agentic: unsafe Jackson default typing in AgenticScope deserialization allows arbitrary class instantiationCVE-2026-97869 · LangChain4j agentic module (AgenticScopeSerializer JSON deserialization)Low
- Langchain-Chatchat: arbitrary file write outside the upload and knowledge-base directoriesCVE-2026-51882 · Langchain-Chatchat (file upload and knowledge-base endpoints, path traversal)Unscored
- llama.cpp: a crafted GGUF file trips a reachable assertion and aborts the process loading itCVE-2026-52131 · llama.cpp (gguf_reader::read GGUF model file parser)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.