Ggml

Llama.Cpp

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 06.08.2026 22:17:06
  • Zuletzt bearbeitet 21.09.2026 18:11:15

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task...

  • EPSS 0.36%
  • Veröffentlicht 06.08.2026 22:17:06
  • Zuletzt bearbeitet 21.09.2026 18:11:21

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attack...

  • EPSS 0.44%
  • Veröffentlicht 06.08.2026 22:17:06
  • Zuletzt bearbeitet 21.09.2026 18:11:28

llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end of the allocated cells array. A...

  • EPSS 0.51%
  • Veröffentlicht 06.08.2026 22:17:05
  • Zuletzt bearbeitet 21.09.2026 18:11:47

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_...

  • EPSS 0.19%
  • Veröffentlicht 06.08.2026 22:17:05
  • Zuletzt bearbeitet 21.09.2026 18:11:56

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_leng...

  • EPSS 0.14%
  • Veröffentlicht 06.08.2026 22:17:05
  • Zuletzt bearbeitet 21.09.2026 18:12:04

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially ...

  • EPSS 0.13%
  • Veröffentlicht 06.08.2026 15:27:07
  • Zuletzt bearbeitet 04.09.2026 18:15:15

llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corru...

  • EPSS 0.42%
  • Veröffentlicht 27.07.2026 00:15:12
  • Zuletzt bearbeitet 27.07.2026 20:25:13

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The...

Exploit
  • EPSS 1.13%
  • Veröffentlicht 01.04.2026 16:59:59
  • Zuletzt bearbeitet 30.04.2026 19:18:32

llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenticated attacker can read and write arbitrary process m...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 24.03.2026 00:01:40
  • Zuletzt bearbeitet 30.04.2026 17:01:02

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This cau...