PT-2026-79788 · Debian+2 · Llama.Cpp

·

CVE-2026-78147

·

Published

2026-08-23

·

Updated

2026-08-31

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions llama.cpp version bec4772f6
Description A deserialization flaw exists in the ggml-RPC Server component. A remote attacker can trigger this issue by manipulating the op or op params arguments within the deserialize tensor() function located in the ggml/src/ggml-rpc/ggml-rpc.cpp file. Deserialization is the process of converting a data format (like a byte stream) back into an object that the program can use.
Recommendations As a temporary mitigation, restrict access to the ggml-RPC Server or avoid using the deserialize tensor() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78147

Affected Products

Llama.Cpp