Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17512

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 3.3

Описание

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.

A flaw was found in whisper.cpp. A local attacker can exploit an out-of-bounds read vulnerability in the log_mel_spectrogram function. This flaw could lead to the disclosure of sensitive information.

Отчет

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the affected packages, refer to the linked references.

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2507460whisper.cpp: whisper.cpp: Information disclosure via out-of-bounds read

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
21 день назад

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.

CVSS3: 3.3
nvd
21 день назад

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.

CVSS3: 3.3
debian
21 день назад

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This ...

CVSS3: 3.3
github
21 день назад

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.

3.3 Low

CVSS3