llama.cpp 版本在 b11393 之前,在 函数中存在使用后释放(use-after-free)和重复释放(double free)漏洞。该漏洞允许未认证的远程攻击者通过悬空的 current_tool 指针破坏堆内存。攻击者可以在 POST /completion 请求中提交一个 chat_parser,在 tool-close 标签后发出 tool-id,从而导致 llama-server 崩溃,并构造出堆写入原语(heap write primitive)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet