漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion
Vulnerability Description
A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation of the argument ne results in reachable assertion. The attack is possible to be carried out remotely. The reported GitHub issue was closed automatically due to inactivity.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
可达断言
Vulnerability Title
ggml llama.cpp 异常处理不当漏洞
Vulnerability Description
ggml llama.cpp是ggml组织的一个在本地执行大语言模型推理的引擎。 ggml llama.cpp 0.4.0及之前版本存在异常处理不当漏洞,该漏洞源于RPC Server组件中ggml/src/ggml-rpc/ggml-rpc.cpp文件里的rpc_server::deserialize_tensor函数对参数ne的错误操作,可能导致可达断言,攻击者可远程利用。
CVSS Information
N/A
Vulnerability Type
N/A