<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>CTranslate2 (&lt; 4.8.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ctranslate2--4.8.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 16:28:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ctranslate2--4.8.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Heap-Based Buffer Overflow in CTranslate2 Binary Model Loader</title><link>https://feed.craftedsignal.io/briefs/2026-09-ctranslate2-buffer-overflow/</link><pubDate>Tue, 29 Sep 2026 16:28:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ctranslate2-buffer-overflow/</guid><description>A heap-based buffer overflow vulnerability in the CTranslate2 binary model loader allows attackers to achieve arbitrary code execution via maliciously crafted model files.</description><content:encoded><![CDATA[<p>CTranslate2 versions prior to 4.8.1 contain a heap-based buffer overflow vulnerability residing in the binary model loader. The flaw stems from a failure to correctly validate the payload length within a model file against the allocated heap buffer size. By crafting a malicious model file with an oversized payload, an attacker can trigger an out-of-bounds write beyond the intended heap allocation boundaries. This vulnerability is critical for applications utilizing the CTranslate2 engine for model inference, as it provides a path for remote code execution or application-level denial-of-service via process crashes. Defenders should identify all environments where CTranslate2 is deployed and prioritize upgrading to version 4.8.1 or later to mitigate the risk of arbitrary code execution stemming from model ingestion.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows for arbitrary code execution in the context of the process running the CTranslate2 library, or a denial-of-service condition if the overflow triggers a crash. The impact is significant for organizations performing model inference on untrusted or externally sourced machine learning models, potentially exposing the underlying host or container environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of CTranslate2 to version 4.8.1 or later immediately.</li>
<li>Implement strict source validation for all model files processed by the CTranslate2 binary loader to prevent the ingestion of untrusted or malformed binary files.</li>
<li>Monitor process integrity logs for crashes associated with model loading services using CTranslate2, as these may indicate exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>