Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70639

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can supply a malicious, corrupt, or truncated model file to trigger a null context condition, causing a SIGSEGV crash that terminates the Android application process and results in denial of service.

A flaw was found in llama.cpp. A null pointer dereference vulnerability exists in the LLaMA-Android JNI wrapper. This flaw allows an attacker to provide a malicious or corrupt model file, which causes the bench_1model() function to attempt to use an invalid memory address. This leads to a crash of the Android application, resulting in a denial of service (DoS) where the application becomes unavailable.

Отчет

llama.cpp is packaged for Fedora (python-llama-cpp-python, ollama, llama-cpp) as Linux command-line/library builds. This flaw is specific to the LLaMA-Android JNI wrapper's bench_1model() function, which is Android-only code that is not compiled or reachable in the standard Linux RPM builds. No Red Hat/community product is affected.

Меры по смягчению последствий

No mitigation is necessary; the Android-specific vulnerable code path is not present in the shipped Linux packages.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2512286llama.cpp: llama.cpp: Denial of Service in Android JNI wrapper via malicious model file

EPSS

Процентиль: 3%
0.0013
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
25 дней назад

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can supply a malicious, corrupt, or truncated model file to trigger a null context condition, causing a SIGSEGV crash that terminates the Android application process and results in denial of service.

CVSS3: 5.5
nvd
25 дней назад

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can supply a malicious, corrupt, or truncated model file to trigger a null context condition, causing a SIGSEGV crash that terminates the Android application process and results in denial of service.

CVSS3: 5.5
debian
25 дней назад

llama.cpp builds b1886 through b7445 contain a null pointer dereferenc ...

CVSS3: 5.5
github
25 дней назад

llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can supply a malicious, corrupt, or truncated model file to trigger a null context condition, causing a SIGSEGV crash that terminates the Android application process and results in denial of service.

EPSS

Процентиль: 3%
0.0013
Низкий

5.5 Medium

CVSS3