Dao AI Lab FlashAttention是Dao AI Lab团队开源的一个高效且节省内存的注意力机制实现工具。 Dao AI Lab FlashAttention 2.8.3.post1及之前版本存在后置链接漏洞,该漏洞源于hopper/setup.py中的download_and_copy()函数在提取NVIDIA toolchain归档时未验证symlink或过滤tar成员,本地攻击者可在可预测缓存目录中预置symlink,将提取的二进制文件重定向到攻击者选择的位置,从而在构建期间以受害者
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Dao-AILab | flash-attention | ≤ 2.8.3.post1 |
affected |
0816ef12f424c6ec94b057a72c275b14f6e6edb2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dao-AILab | flash-attention | 0 ~ 2.8.3.post1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet