You need to agree to share your contact information to access this model

This repository is publicly accessible, but you have to accept the conditions to access its files and content.

Log in or Sign Up to review the conditions and access this model content.

YAML Metadata Warning:empty or missing yaml metadata in repo card

Check out the documentation for more information.

🧨 Undefined Behavior in llama.cpp GGUF Loader

Summary

This repository demonstrates an undefined behavior bug in the test-gguf binary from the llama.cpp project. The bug is triggered via multiple real-world .gguf vocab model files, including those provided here.

Vulnerability

Due to missing input validation in the GGUF file parsing logic, malformed or unexpected values can trigger an unsigned integer underflow inside C++ STL's std::string::compare():

runtime error: unsigned integer overflow: 6 - 10 cannot be represented in type 'size_type'
SUMMARY: UndefinedBehaviorSanitizer: basic_string.h:495:51

How to Reproduce

πŸ›  Build llama.cpp with UBSan

git clone https://github.com/ggerganov/llama.cpp
cd llama.cpp
mkdir build && cd build
CC=clang CXX=clang++ CFLAGS="-fsanitize=undefined,address -g" \
CXXFLAGS="-fsanitize=undefined,address -g" cmake .. -DLLAMA_BUILD_TESTS=on
make -j$(nproc) test-gguf

πŸ’₯ Trigger the crash

UBSAN_OPTIONS=print_stacktrace=1 ./bin/test-gguf -- ./ggml-vocab-aquila.gguf

You should see output like:

/bits/basic_string.h:495:51: runtime error: unsigned integer overflow
...

Files

  • ggml-vocab-aquila.gguf: Used to reliably trigger the bug

Credit

Discovered by: bigmo6286

Downloads last month
-
GGUF
Model size
0 params
Architecture
bert
Hardware compatibility
Log In to add your hardware

We're not able to determine the quantization variants.

Inference Providers NEW
This model isn't deployed by any Inference Provider. πŸ™‹ Ask for provider support