Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33298

Опубликовано: 24 мар. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the ggml_nbytes function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This causes ggml_nbytes to return a significantly smaller size than required (e.g., 4MB instead of Exabytes), leading to a heap-based buffer overflow when the application subsequently processes the tensor. This vulnerability allows potential Remote Code Execution (RCE) via memory corruption. b7824 contains a fix.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ggml:llama.cpp:*:*:*:*:*:*:*:*
Версия до b7824 (исключая)

EPSS

Процентиль: 39%
0.00477
Низкий

7.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.8
ubuntu
5 месяцев назад

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This causes `ggml_nbytes` to return a significantly smaller size than required (e.g., 4MB instead of Exabytes), leading to a heap-based buffer overflow when the application subsequently processes the tensor. This vulnerability allows potential Remote Code Execution (RCE) via memory corruption. b7824 contains a fix.

CVSS3: 7.8
debian
5 месяцев назад

llama.cpp is an inference of several LLM models in C/C++. Prior to b78 ...

EPSS

Процентиль: 39%
0.00477
Низкий

7.8 High

CVSS3

Дефекты

CWE-122