CVE-2024-21802 is a critical heap-based buffer overflow vulnerability in the GGUF library info->ne functionality of llama.cpp, specifically commit 18c2e17. An attacker can exploit this by providing a specially crafted .gguf file, leading to arbitrary code execution on affected systems. With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector, low attack complexity, and high impacts on confidentiality, integrity, and availability, requiring no user interaction. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, community discussion highlights the risk of using untrusted models with unsafe serialization formats.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024-01-09CPE matchmatch criteria | cpe:2.3:a:ggml:llama.cpp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.