天下漏洞,尽知其名
MEDIUM

CVE-2026-102567 CTranslate2 堆越界读取漏洞

原始情报

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.