llama.cpp 修復 chat-peg-parser 釋放後使用漏洞
llama.cpp 合併 PR #29942,修復 chat-peg-parser 中 pending_tool_call 重置時未清空 current_tool 指標導致的 use-after-free 與 id 緩衝區二次釋放。該問題在 TOOL_CLOSE 之後收到 TOOL_ID 節點時觸發,修復方式是在重置時清除指標。
原標題:b11393
閱讀原文
| 評分 | 38 / 42(平均 40,門檻 60) |
| 狀態 | 未入選 |
|---|
原文
chat-peg-parser : clear current_tool when pending_tool_call is reset ( #29942 )
A TOOL_ID node that arrives after TOOL_CLOSE wrote through current_tool ,
which still pointed into the just-destroyed pending_tool_call optional
(use-after-free, then a second free of the id buffer). Clear the pointer on
reset.
Website:
https://llama.app
Attestations:
https://github.com/ggml-org/llama.cpp/attestations/52608917
macOS/iOS:
macOS Apple Silicon (arm64)
macOS Apple Silicon (arm64, KleidiAI enabled) DISABLED
macOS Intel (x64)
iOS XCFramework
Linux:
Ubuntu x64 (CPU)
Ubuntu arm64 (CPU)
Ubuntu s390x (CPU)
Ubuntu x64 (Vulkan)
Ubuntu arm64 (Vulkan)
Ubuntu x64 (CUDA 12) - CUDA 12.8 libraries
Ubuntu x64 (CUDA 13) - CUDA 13.4 libraries
Ubuntu arm64 (CUDA 13) - CUDA 13.4 libraries
Ubuntu x64 (ROCm 10.0)
Ubuntu x64 (OpenVINO)
Ubuntu x64 (SYCL FP32)
Ubuntu x64 (SYCL FP16)
Linux arm64 (Snapdragon: CPU, Adreno GPU, Hexagon NPU) - setup guide
Android:
Android arm64 (CPU)
Android arm64 (Snapdragon: CPU, Adreno GPU, Hexagon NPU) - setup guide
Windows:
Windows x64 (CPU)
Windows arm64 (CPU)
Windows arm64 (OpenCL Adreno)
Windows x64 (CUDA 12) - CUDA 12.4 DLLs
Windows x64 (CUDA 13) - CUDA 13.4 DLLs
Windows arm64 (CUDA 13) - CUDA 13.4 DLLs
Windows x64 (Vulkan)
Windows x64 (OpenVINO)
Windows x64 (SYCL)
Windows x64 (ROCm 10.0)
openEuler:
DISABLED
openEuler x86 (310p)
openEuler x86 (910b, ACL Graph)
openEuler aarch64 (310p)
openEuler aarch64 (910b, ACL Graph)
UI:
UI
相關報導
llama.cpp releases10/4 11:22AI 評分42
llama.cpp 發布 b11387 版本,修復了在截斷後溫度大於 0 時 n-gram 草稿被拒絕的問題(PR #29924),由 NVIDIA 的 Pranesh Gonegandla 參與提交。
llama.cpp releases10/5 09:36AI 評分48
llama.cpp 發布 b11412,修復 k-pool 模型(qwen4exp、glm5-next)解碼時意外重新預留計算圖並中止的問題。原因是兩模型按 cache_safe、n_tokens 等 reserve 無法預知的狀態分支,解碼圖與預留圖節點數不一致(如 7564 對 7762),解碼時被迫按當前狀態重預留、丟掉最壞情況尺寸,在 GGML_SCHED_DEBUG_REALLOC=1 下直接 abort。
llama.cpp releases10/4 13:56AI 評分37
llama.cpp 發布建置版本 b11390,主要修復了 CUDA 後端在 n_expert 遠大於 n_ubatch 時的 MMQ 記憶體故障(#29941)。
llama.cpp releases10/5 15:50AI 評分42
llama.cpp 發布 b11424 建置版本,修復 Vulkan 後端 Flash Attention 的共享記憶體越界寫問題(#29988)。該版本照例提供 macOS/iOS、Linux、Windows、Android 的預編譯包,涵蓋 Vulkan、CUDA 12/13、ROCm 10.0、OpenVINO、SYCL、OpenCL 等後端,並附驍龍 CPU/Adreno GPU/Hexagon NPU 的安裝指引。
llama.cpp releases10/5 09:19AI 評分12
llama.cpp 發布 b11407 版本,修復了在開啟 -DGGML_VULKAN_RUN_TESTS=ON 時 Vulkan 後端出現的未宣告識別符號問題。該版本同步提供 macOS、Linux、Windows、Android 等多平台預編譯包,涵蓋 CPU、CUDA 12/13、Vulkan、ROCm 10.0、OpenVINO、SYCL 及 Snapdragon 的 Adreno GPU 與 Hexagon NPU 等後端。