CVE-2026-43629

EUVD-2026-54284
llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt heap memory. Attackers can craft malicious state files where cell_count multiplication overflows or exceeds tensor buffer allocation to write attacker-controlled bytes past buffer boundaries, potentially resulting in heap metadata corruption, model weight corruption, or arbitrary code execution via function pointer overwrite.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulnCheckCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40.54%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ggmlllama.cpp
0.16.1 ≤
𝑥
≤ 0.17.1
CNA
Debian logo
Debian Releases
Debian Product
Codename
llama.cpp
forky
undetermined
sid
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
llama.cpp
jammy
dne
noble
dne
resolute
needs-triage