CVE-2024-42477: Ggml Llama.cpp
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buffer-overflow`. This vulnerability may lead to memory data leakage. The vulnerability is fixed in b3561.
Affected products
- Ggml Llama.cpp: before b3561 (fixed in b3561)
Published 2024-08-12. Last modified 2026-06-17.