Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion
Vulnerability Description
A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation of the argument ne results in reachable assertion. The attack is possible to be carried out remotely. The reported GitHub issue was closed automatically due to inactivity.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
可达断言
Vulnerability Title
ggml llama.cpp 异常处理不当漏洞
Vulnerability Description
ggml llama.cpp是ggml组织的一个在本地执行大语言模型推理的引擎。 ggml llama.cpp 0.4.0及之前版本存在异常处理不当漏洞,该漏洞源于RPC Server组件中ggml/src/ggml-rpc/ggml-rpc.cpp文件里的rpc_server::deserialize_tensor函数对参数ne的错误操作,可能导致可达断言,攻击者可远程利用。
CVSS Information
N/A
Vulnerability Type
N/A