在 ggml-org llama.cpp 的 bec4772f6 版本中发现了一个漏洞。该漏洞影响位于组件 ggml-RPC Server 中的文件 ggml/src/ggml-rpc/ggml-rpc.cpp 里的函数 rpc_server::graph_compute。执行恶意操纵可能导致空指针解引用(null pointer dereference)。该攻击可从远程发起。目前,修复此问题的拉取请求(pull request)尚待合并接受。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet