CVE-2024-21836
Homebrew vulnerability analysis and mitigation

Overview

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. The vulnerability was discovered in January 2024 and affects the LLaMA.cpp implementation, which is used for running LLaMA models. This security flaw has been assigned CVE-2024-21836 and has received a high severity CVSS v3.1 score of 8.8 (Talos Intelligence).

Technical details

The vulnerability stems from an integer overflow in the GGUF file parsing functionality. When processing the header.n_tensors value, which is an arbitrary uint64_t value, multiplication with sizeof(struct gguf_tensor_info) (88 bytes) can lead to an integer overflow. This results in allocating fewer elements than required, potentially causing a heap-based buffer overflow when writing the pointer to a string in info->name. The issue is classified under CWE-190 (Integer Overflow or Wraparound) (Talos Intelligence).

Impact

The vulnerability allows for potential code execution through a specially crafted .gguf file. Given the CVSS score of 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), the impact is considered high, potentially affecting confidentiality, integrity, and availability of the system (Talos Intelligence).

Mitigation and workarounds

The vulnerability has been fixed in versions after Commit 18c2e17. Databricks independently reported this vulnerability concurrently with Cisco Talos's discovery. The vendor released a patch on January 29, 2024 (Talos Intelligence).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21679CRITICAL9.8
  • HomebrewHomebrew
  • iccdev
NoYesJan 07, 2026
CVE-2026-21504HIGH7.8
  • HomebrewHomebrew
  • iccdev
NoYesJan 07, 2026
CVE-2026-21680HIGH7.5
  • HomebrewHomebrew
  • iccdev
NoYesJan 07, 2026
CVE-2026-21503MEDIUM5.5
  • HomebrewHomebrew
  • iccdev
NoYesJan 07, 2026
CVE-2026-21502MEDIUM5.5
  • HomebrewHomebrew
  • iccdev
NoYesJan 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management