A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the …
Medium CVSS 4.3
Summary
A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the component GGUF Tokenizer. The manipulation of the argument eos_token_id/bos_token_id/unknown_token_id results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 0.8.23 can resolve this issue. The patch is identified as cd5297e2…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/EricLBuehler/mistral.rs/
- https://github.com/EricLBuehler/mistral.rs/commit/cd5297e2ea5cb27c790bdcf2f3c2f1064a81d55e
- https://github.com/EricLBuehler/mistral.rs/issues/2225
- https://github.com/EricLBuehler/mistral.rs/pull/2282
- https://github.com/EricLBuehler/mistral.rs/releases/tag/v0.8.23
- https://vuldb.com/cve/CVE-2026-75090
- https://vuldb.com/submit/877270
- https://vuldb.com/vuln/391327
- https://vuldb.com/vuln/391327/cti
Timeline
- nvd_ingest NVD