Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43627

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.

A flaw was found in llama.cpp. An integer overflow vulnerability exists in the llama_batch_init() function due to unchecked multiplications during memory allocation. Attackers can provide specially crafted input parameters, leading to heap corruption. This could potentially allow for arbitrary code execution through subsequent operations that write beyond allocated memory boundaries.

Отчет

Exploitation requires convincing a user or local process to execute inference workloads using maliciously oversized batch sizing parameters, leading to an arithmetic overflow during memory allocation and subsequent heap corruption. Full impact across Confidentiality, Integrity, and Availability (C:H, I:H, A:H) is possible if local memory execution controls fail, potentially resulting in arbitrary code execution within the application context. Deployments operating strictly with validated, bounded batch size inputs or running non-interactive server pipelines where batch parameters are hard-coded or strictly validated are unaffected.

Меры по смягчению последствий

To reduce the risk, avoid processing untrusted or malicious input with applications that use the llama.cpp library. Deploying applications that utilize llama.cpp within a sandboxed environment can further limit the potential impact of successful exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2512353llama.cpp: llama.cpp: Arbitrary Code Execution via Integer Overflow in Memory Allocation

EPSS

Процентиль: 4%
0.00139
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 дней назад

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.

CVSS3: 7.8
nvd
8 дней назад

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.

CVSS3: 7.8
debian
8 дней назад

llama.cpp builds b1283 through b9058 contain an integer overflow vulne ...

CVSS3: 7.8
github
8 дней назад

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.

EPSS

Процентиль: 4%
0.00139
Низкий

7.8 High

CVSS3