AISpot

llama.cpp 修復 ggml_acc 負偏移導致的越界寫

llama.cpp releases版本更新地端推論開源

llama.cpp 建置 b11529 修復了 ggml 中 ggml_acc 的越界寫漏洞:ggml_acc_impl 將 size_t 偏移量收窄為 int32_t 時未做檢查,超大偏移會截斷成負數,再被符號擴充套件為巨大 size_t 導致邊界斷言失效,可在 dst 緩衝區下方越界寫入。修復方式是在收窄前檢查偏移量,與 ggml_set_impl 中已有檢查保持一致。該版本同時提供 macOS、Linux、Windows、Android 等多平台預編譯包。

原標題:b11529
閱讀原文

評分45 / 48(平均 46,門檻 60)
狀態未入選

原文

ggml: fix OOB write in ggml_acc with negative offset ( #30135 ) ggml_acc_impl narrowed a size_t offset to int32_t without checking that it fits, so a large offset could truncate to a negative int32_t. The forward then sign-extended it to a huge size_t and the bounds assertion wrapped, allowing an OOB write below the dst buffer. Check the offset before the narrowing, matching the existing check in ggml_set_impl. Website: https://llama.app Attestations: https://github.com/ggml-org/llama.cpp/attestations/54364695 macOS/iOS: macOS Apple Silicon (arm64) macOS Apple Silicon (arm64, KleidiAI enabled) DISABLED macOS Intel (x64) iOS XCFramework Linux: Ubuntu x64 (CPU) Ubuntu arm64 (CPU) Ubuntu s390x (CPU) Ubuntu x64 (Vulkan) Ubuntu arm64 (Vulkan) Ubuntu x64 (CUDA 12) - CUDA 12.8 libraries Ubuntu x64 (CUDA 13) - CUDA 13.4 libraries Ubuntu arm64 (CUDA 13) - CUDA 13.4 libraries Ubuntu x64 (ROCm 10.0) Ubuntu x64 (OpenVINO) Ubuntu x64 (SYCL FP32) Ubuntu x64 (SYCL FP16) Linux arm64 (Snapdragon: CPU, Adreno GPU, Hexagon NPU) - setup guide Android: Android arm64 (CPU) Android arm64 (Snapdragon: CPU, Adreno GPU, Hexagon NPU) - setup guide Windows: Windows x64 (CPU) Windows arm64 (CPU) Windows arm64 (OpenCL Adreno) Windows x64 (CUDA 12) - CUDA 12.4 DLLs Windows x64 (CUDA 13) - CUDA 13.4 DLLs Windows arm64 (CUDA 13) - CUDA 13.4 DLLs Windows x64 (Vulkan) Windows arm64 (Vulkan) Windows x64 (OpenVINO) Windows x64 (SYCL) Windows x64 (ROCm 10.0) openEuler: DISABLED openEuler x86 (310p) openEuler x86 (910b, ACL Graph) openEuler aarch64 (310p) openEuler aarch64 (910b, ACL Graph) UI: UI

相關報導

llama.cpp releasesAI 評分42

llama.cpp 發布 b11424,修復 Vulkan Flash Attention 共享記憶體越界寫

llama.cpp 發布 b11424 建置版本,修復 Vulkan 後端 Flash Attention 的共享記憶體越界寫問題(#29988)。該版本照例提供 macOS/iOS、Linux、Windows、Android 的預編譯包,涵蓋 Vulkan、CUDA 12/13、ROCm 10.0、OpenVINO、SYCL、OpenCL 等後端,並附驍龍 CPU/Adreno GPU/Hexagon NPU 的安裝指引。

llama.cpp releasesAI 評分12

llama.cpp 發布 b11407,修復 Vulkan 測試編譯錯誤

llama.cpp 發布 b11407 版本,修復了在開啟 -DGGML_VULKAN_RUN_TESTS=ON 時 Vulkan 後端出現的未宣告識別符號問題。該版本同步提供 macOS、Linux、Windows、Android 等多平台預編譯包,涵蓋 CPU、CUDA 12/13、Vulkan、ROCm 10.0、OpenVINO、SYCL 及 Snapdragon 的 Adreno GPU 與 Hexagon NPU 等後端。