CVE-2026-102567
6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenNMT | CTranslate2 | 0 < 4.8.1 | affected |
| OpenNMT | CTranslate2 | 4.8.1 | unaffected |
Weaknesses
- CWE-125: Out-of-bounds Read
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/OpenNMT/CTranslate2/pull/2068
- https://github.com/OpenNMT/CTranslate2/commit/d9b991e0700933a0c05373df8b52ed89cdcab96d
- https://github.com/OpenNMT/CTranslate2/blob/v4.8.0/src/models/model.cc#L81-L87
- https://github.com/OpenNMT/CTranslate2/releases/tag/v4.8.1
- https://github.com/OpenNMT/CTranslate2
- https://www.vulncheck.com/advisories/ctranslate2-before-4.8.1-out-of-bounds-read-via-model-deserialization
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.