CVE-2026-43627

EUVD-2026-54281
llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulnCheckCNA
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.7%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ggmlllama.cpp
0.4.0 ≤
𝑥
≤ 0.17.1
CNA
Debian logo
Debian Releases
Debian Product
Codename
llama.cpp
forky
undetermined
sid
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
llama.cpp
jammy
dne
noble
dne
resolute
needs-triage