Back to Database
Status published
Medium
CVE-2024-42477
llama.cpp global-buffer-overflow in ggml_type_size
Vulnerability Description
llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buffer-overflow`. This vulnerability may lead to memory data leakage. The vulnerability is fixed in b3561.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-42477
Credits & Attribution
No credits recorded in the NVD database.
References
More from ggerganov
View All →CVE-2024-42479
llama.cpp allows write-what-where in rpc_server::set_tensor
Critical
10
CVE-2024-42478
llama.cpp allows Arbitrary Address Read in rpc_server::get_tensor
Medium
5.3
CVE-2024-41130
llama.cpp null pointer dereference in gguf_init_from_file
Medium
5.4
CVE-2024-32878
Use of Uninitialized Variable Vulnerability in llama.cpp
High
7.1
Affected Vendor
ggerganov
View all reports →Affected Software
llama.cpp
Vulnerable Versions:
< b3561
Timeline
Official Publish:
August 12th, 2024
Last Modified:
August 13th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N