CVE-2025-62609: MLX has Wild Pointer Dereference in load_gguf()
Segmentation fault in mlx::core::load_gguf() when loading malicious GGUF files. Untrusted pointer from external gguflib library is dereferenced without validation, causing application crash.
Environment:
- OS: Ubuntu 20.04.6 LTS
- Compiler: Clang 19.1.7
References
Code Behaviors & Features
Detect and mitigate CVE-2025-62609 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →