PT-2026-79400 · Llama.Cpp · Llama.Cpp
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
llama.cpp versions prior to b8585
Description
A use-after-free issue exists in the RPC server's
GRAPH RECOMPUTE handler. This occurs when a computation graph is stored and its referenced buffers are subsequently freed, allowing the freed memory to be reclaimed with attacker-controlled content. Unauthenticated remote attackers can trigger the re-execution of these stored graphs using dangling pointers—pointers that still reference memory locations after they have been freed—to achieve arbitrary read and write access, potentially leading to full remote code execution without user interaction.Recommendations
Update llama.cpp to version b8585 or later.
Exploit
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Llama.Cpp