PT-2026-68729 · Llama.Cpp · Llama.Cpp
CVE-2026-43630
·
Published
2026-08-06
·
Updated
2026-08-07
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
llama.cpp versions b5702 through b7653
Description
An out-of-bounds read exists in the recurrent memory state restore path. Attackers with write access to the slot save directory can craft a malicious slot file containing an oversized
seq id value. This triggers a read operation past the end of the allocated cells array, leaking heap data and pointer values into server logs. This process defeats Address Space Layout Randomization (ASLR), a security technique that randomly arranges the address space positions of key data areas of a process, thereby facilitating further exploitation.Recommendations
Update llama.cpp to a version later than b7653.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Llama.Cpp