CyberRota Analysis
AI-GeneratedCTranslate2 versions prior to 4.8.1 are susceptible to a heap-based buffer overflow in the binary model loader due to inadequate validation of payload lengths against allocated buffer sizes. This vulnerability allows attackers to create malicious model files that can lead to crashes or arbitrary code execution. Organizations utilizing CTranslate2 should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.