CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
OpenNMT · CTranslate2References
https://github.com/OpenNMT/CTranslate2https://github.com/OpenNMT/CTranslate2/blob/v4.8.0/src/models/model.cc#L656-L657https://github.com/OpenNMT/CTranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96dhttps://github.com/OpenNMT/CTranslate2/pull/2068https://github.com/OpenNMT/CTranslate2/releases/tag/v4.8.1https://www.vulncheck.com/advisories/ctranslate2-before-4.8.1-heap-buffer-overflow-via-model-bin