freenode
AI & ML

llama.cpp GGUF reader accepts out-of-range type before checks

A crafted metadata key length can push an invalid enum into the parser, triggering undefined behavior on untrusted model files.

The GGUF metadata reader in llama.cpp can load an out-of-range type value from an untrusted file into an enum before any validation runs, according to a bug report from am17an.

GGUF is the on-disk format llama.cpp uses for model weights and key/value metadata. For each metadata entry the reader takes a type field straight from the file and uses it in comparisons and a switch before confirming it is one of the defined enumerators (0 through 12). A forged key-length prefix can leave the parser reading later bytes of a legitimate key string as that type, producing a value far outside the valid range.

The reporter demonstrated the fault with a 640-byte crafted container: the first key/value entry alone is enough to hit the bad path. On a build with undefined-behavior sanitizers the load is visible as an out-of-range enum use; without sanitizers the same input is simply undefined behavior during parse of any untrusted GGUF.

Anyone who opens third-party or user-supplied GGUF files in llama.cpp or other GGML-based tools is exposed until the reader rejects invalid type values before treating them as enumerators.