Unauthenticated arbitrary memory write via RPC tensor pointer
Published Aug 12, 2024 · Updated Aug 13, 2024
Write-what-where in llama.cpp before b3561 allows remote attackers to overwrite arbitrary process memory through the RPC server. rpc_server::set_tensor trusts the serialized rpc_tensor.data pointer and passes it to ggml_backend_cpu_buffer_set_tensor, where memcpy writes supplied bytes without checking that the destination lies inside the allocated backend buffer. RPC network reachability is the only gate; unauthenticated requests enable process crashes and an arbitrary-write primitive that supports code execution when paired with an address-read primitive.
Summary
What happened
Write-what-where in llama.cpp before b3561 allows remote attackers to overwrite arbitrary process memory through the RPC server. rpc_server::set_tensor trusts the serialized rpc_tensor.data pointer and passes it to ggml_backend_cpu_buffer_set_tensor, where memcpy writes supplied bytes without checking that the destination lies inside the allocated backend buffer. RPC network reachability is the only gate; unauthenticated requests enable process crashes and an arbitrary-write primitive that supports code execution when paired with an address-read primitive.
The record
- CVE
- CVE-2024-42479
- Published
- Aug 12, 2024
- Updated
- Aug 13, 2024
- Vendor
- Georgi Gerganov
- Product
- llama.cpp
- Classifications
- CWE-123, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 12, 2024CVE publishedPublication date reported by the CVE source.
- Aug 13, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <b3561
- Affected versionversion=< b3561
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- Upstream SET_TENSOR proof of conceptfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo