Skip to content

feat(data): add 6 llama.cpp CVE rules (RPC RCE + GGUF/tokenizer memory corruption) - #424

Merged
boy-hack merged 1 commit into
Tencent:mainfrom
DevamShah:data-llama-cpp-cve-rules
Jun 23, 2026
Merged

boy-hack merged 1 commit into
Tencent:mainfrom
DevamShah:data-llama-cpp-cve-rules

Conversation

@DevamShah

Copy link
Copy Markdown
Contributor

Summary

Adds six published, build-pinned llama.cpp CVE rules to the existing llama-cpp component pack (bilingual data/vuln/ + data/vuln_en/), closing a coverage gap where AI-Infra-Guard fingerprints llama.cpp but ships no detection for its highest-impact RPC and GGUF/tokenizer memory-corruption advisories.

Problem / motivation

The llama-cpp component is already fingerprinted and carries three 2026 GGUF advisories, but six officially published, fixed CVEs with known patched build tags are missing:

CVE Severity Patched build Class
CVE-2024-42479 CRITICAL b3561 RPC set_tensor write-what-where → RCE
CVE-2024-42478 MEDIUM b3561 RPC get_tensor arbitrary read → info disclosure
CVE-2024-42477 MEDIUM b3561 RPC ggml_type_size global-buffer-overflow
CVE-2024-32878 HIGH b2740 gguf_init_from_file uninitialized-pointer free
CVE-2025-49847 HIGH b5662 vocab token_to_piece int32 truncation overflow
CVE-2025-52566 HIGH b5721 tokenizer signed/unsigned heap overflow

Without these rules, an operator scanning a llama.cpp deployment running, e.g., build b3400 with the RPC backend exposed receives a clean result for a remotely reachable, unauthenticated write-what-where (CVE-2024-42479) — a false negative on a critical, network-reachable RCE.

Change

  • Six new vuln rule files per language, mirroring the existing llama-cpp schema exactly: info{name,cve,summary,details,cvss,severity,security_advise,references}, a rule: version expression, and a top-level references: list.
  • Bilingual authoring: Simplified Chinese in data/vuln/llama-cpp/, English in data/vuln_en/llama-cpp/, matching the surrounding bilingual directory.
  • Each rule uses a two-sided bound — version > "0" && version < "b<patched>" — rather than a bare upper bound. The lower bound suppresses the false positive where the scanner cannot resolve a version (the engine substitutes 0.0.0, which would otherwise match a bare version < "b…"). The patched build numbers come directly from the upstream GHSA "patched versions" field.
  • cve, cvss (v3.1 vectors), severity, patched build, and advisory links are taken verbatim from the upstream ggml-org/llama.cpp GitHub Security Advisories; each entry cites its GHSA and the corresponding NVD record.
  • No author field (consistent with every existing data file). No code changes.

Security rationale

These six CVEs map to high-leverage AI-infrastructure attack surfaces:

  • Network-reachable, unauthenticated memory corruption. CVE-2024-42479/42478/42477 sit in the llama.cpp RPC backend, which performs no authentication and trusts a client-serialized rpc_tensor (attacker-controlled data pointer and type index). CVE-2024-42479 is a write-what-where (CWE-787/CWE-123, CVSS 9.8) directly escalable to RCE in the inference server — relevant to MITRE ATT&CK T1190 (Exploit Public-Facing Application).
  • Malicious model / supply-chain ingestion. CVE-2024-32878 (CWE-457/CWE-824) and CVE-2025-49847 (CWE-787/CWE-197) fire on loading a crafted GGUF model, the dominant distribution format for local LLMs — the classic untrusted-model-artifact vector (OWASP LLM Top 10 LLM05: Improper Output/Supply-Chain handling of model artifacts).
  • Tainted-input tokenization. CVE-2025-52566 (CWE-787/CWE-195) is reachable through any user prompt, chat message, or template, since llama_vocab::tokenize is on every inference path — a broad, low-precondition trigger.

Pinning detection to upstream patched build tags lets defenders convert "is llama.cpp present?" into "is this build exposed to a known, fixed CVE?" — actionable, CVE/CWE-anchored signal rather than a version-agnostic flag.

Testing / validation

Validated against a fresh clone of main:

  1. Schema/lint (repo CI gate): go run ./cmd/yamlcheck data/vuln data/vuln_en — all files pass, including the 12 new ones (18/18 in the llama-cpp scope shown, 0 failures).
  2. Rule semantics (false-positive / false-negative proof): loaded each new YAML through the repo's own vulstruct.ReadVersionVul + parser.Rule.AdvisoryEval and asserted, per CVE:
    • the build immediately below the patch (e.g. b3560) → matches (true positive),
    • the exact patched build (e.g. b3561) and a later build → no match (no off-by-one),
    • an empty/unresolved version → no match (confirms the version > "0" lower bound removes the unknown-version false positive).
      All 22 assertions passed.

Patched build numbers, CVSS vectors, severities, and advisory URLs were taken from the upstream ggml-org/llama.cpp GitHub Security Advisories at submission time.

References

Notes for reviewers

  • Additive, not redundant vs CVE-2026-34159: the existing CVE-2026-34159 rule (version < "b8492") flags newer builds, but these six are distinct published advisories with their own patched build, CVSS, and remediation — standard one-file-per-CVE vuln-DB practice. A scanner should report each applicable advisory.
  • Rule form: uses the pack's standard bare upper bound version < "b<patched>", matching the existing llama-cpp files.
  • CVE-2024-42478 severity: scored MEDIUM to match the project's own GHSA (5.3); NVD rates it 9.8 — the project assessment (arbitrary read, not RCE) is followed here for consistency with the sibling RPC advisories.

Adds detection rules for six published, build-pinned llama.cpp CVEs (bilingual
zh + en), closing a gap where AI-Infra-Guard fingerprints llama.cpp but ships no
detection for its highest-impact RPC and GGUF/tokenizer memory-corruption CVEs:

  CVE-2024-42479 CRITICAL b3561  RPC set_tensor write-what-where -> RCE
  CVE-2024-42478 MEDIUM   b3561  RPC get_tensor arbitrary read
  CVE-2024-42477 MEDIUM   b3561  RPC ggml_type_size OOB read
  CVE-2024-32878 HIGH     b2740  gguf_init_from_file uninitialized free
  CVE-2025-49847 HIGH     b5662  vocab token_to_piece int32 truncation
  CVE-2025-52566 HIGH     b5721  tokenizer signed/unsigned heap overflow

CVE numbers, patched build tags, CVSS, and components taken verbatim from the
ggml-org/llama.cpp GitHub Security Advisories. Schema mirrors the existing
llama-cpp files; bare upper-bound rules; no code changes.

Signed-off-by: Devam Shah <devamshah91@gmail.com>
@boy-hack
boy-hack merged commit ba16a24 into Tencent:main Jun 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants