Repository navigation
feat(data): add 6 llama.cpp CVE rules (RPC RCE + GGUF/tokenizer memory corruption) - #424
Merged
Merged
Conversation
Adds detection rules for six published, build-pinned llama.cpp CVEs (bilingual zh + en), closing a gap where AI-Infra-Guard fingerprints llama.cpp but ships no detection for its highest-impact RPC and GGUF/tokenizer memory-corruption CVEs: CVE-2024-42479 CRITICAL b3561 RPC set_tensor write-what-where -> RCE CVE-2024-42478 MEDIUM b3561 RPC get_tensor arbitrary read CVE-2024-42477 MEDIUM b3561 RPC ggml_type_size OOB read CVE-2024-32878 HIGH b2740 gguf_init_from_file uninitialized free CVE-2025-49847 HIGH b5662 vocab token_to_piece int32 truncation CVE-2025-52566 HIGH b5721 tokenizer signed/unsigned heap overflow CVE numbers, patched build tags, CVSS, and components taken verbatim from the ggml-org/llama.cpp GitHub Security Advisories. Schema mirrors the existing llama-cpp files; bare upper-bound rules; no code changes. Signed-off-by: Devam Shah <devamshah91@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds six published, build-pinned llama.cpp CVE rules to the existing
llama-cppcomponent pack (bilingualdata/vuln/+data/vuln_en/), closing a coverage gap where AI-Infra-Guard fingerprints llama.cpp but ships no detection for its highest-impact RPC and GGUF/tokenizer memory-corruption advisories.Problem / motivation
The
llama-cppcomponent is already fingerprinted and carries three 2026 GGUF advisories, but six officially published, fixed CVEs with known patched build tags are missing:set_tensorwrite-what-where → RCEget_tensorarbitrary read → info disclosureggml_type_sizeglobal-buffer-overflowgguf_init_from_fileuninitialized-pointer freetoken_to_pieceint32 truncation overflowWithout these rules, an operator scanning a llama.cpp deployment running, e.g., build b3400 with the RPC backend exposed receives a clean result for a remotely reachable, unauthenticated write-what-where (CVE-2024-42479) — a false negative on a critical, network-reachable RCE.
Change
llama-cppschema exactly:info{name,cve,summary,details,cvss,severity,security_advise,references}, arule:version expression, and a top-levelreferences:list.data/vuln/llama-cpp/, English indata/vuln_en/llama-cpp/, matching the surrounding bilingual directory.ruleuses a two-sided bound —version > "0" && version < "b<patched>"— rather than a bare upper bound. The lower bound suppresses the false positive where the scanner cannot resolve a version (the engine substitutes0.0.0, which would otherwise match a bareversion < "b…"). The patched build numbers come directly from the upstream GHSA "patched versions" field.cve,cvss(v3.1 vectors),severity, patched build, and advisory links are taken verbatim from the upstream ggml-org/llama.cpp GitHub Security Advisories; each entry cites its GHSA and the corresponding NVD record.authorfield (consistent with every existing data file). No code changes.Security rationale
These six CVEs map to high-leverage AI-infrastructure attack surfaces:
rpc_tensor(attacker-controlleddatapointer andtypeindex). CVE-2024-42479 is a write-what-where (CWE-787/CWE-123, CVSS 9.8) directly escalable to RCE in the inference server — relevant to MITRE ATT&CK T1190 (Exploit Public-Facing Application).llama_vocab::tokenizeis on every inference path — a broad, low-precondition trigger.Pinning detection to upstream patched build tags lets defenders convert "is llama.cpp present?" into "is this build exposed to a known, fixed CVE?" — actionable, CVE/CWE-anchored signal rather than a version-agnostic flag.
Testing / validation
Validated against a fresh clone of
main:go run ./cmd/yamlcheck data/vuln data/vuln_en— all files pass, including the 12 new ones (18/18 in thellama-cppscope shown, 0 failures).vulstruct.ReadVersionVul+parser.Rule.AdvisoryEvaland asserted, per CVE:b3560) → matches (true positive),b3561) and a later build → no match (no off-by-one),version > "0"lower bound removes the unknown-version false positive).All 22 assertions passed.
Patched build numbers, CVSS vectors, severities, and advisory URLs were taken from the upstream ggml-org/llama.cpp GitHub Security Advisories at submission time.
References
Notes for reviewers
CVE-2026-34159: the existingCVE-2026-34159rule (version < "b8492") flags newer builds, but these six are distinct published advisories with their own patched build, CVSS, and remediation — standard one-file-per-CVE vuln-DB practice. A scanner should report each applicable advisory.version < "b<patched>", matching the existingllama-cppfiles.