MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This issue has been patched in version 0.29.4.
History

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Ml-explore
Ml-explore mlx
Vendors & Products Ml-explore
Ml-explore mlx

Sat, 22 Nov 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Fri, 21 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Description MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash. This issue has been patched in version 0.29.4.
Title MLX has Wild Pointer Dereference in load_gguf()
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-21T19:09:33.874Z

Reserved: 2025-10-16T19:24:37.268Z

Link: CVE-2025-62609

cve-icon Vulnrichment

Updated: 2025-11-21T19:09:30.033Z

cve-icon NVD

Status : Received

Published: 2025-11-21T19:16:02.467

Modified: 2025-11-21T19:16:02.467

Link: CVE-2025-62609

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-11-21T18:57:45Z

Links: CVE-2025-62609 - Bugzilla