CVE-2026-43627
llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-190, CWE-680, CWE-190, CWE-680
- Published
- 2026-08-06
- Last modified
- 2026-08-14
Affected products
- ggml-org llama.cpp
- ggml-org llama.cpp
Weakness type
Related vulnerabilities
- CVE-2026-87020 — Orthanc DICOM Server Integer Overflow or Wraparound
- CVE-2026-89146 — libp2p-rendezvous through 0.17.1 Denial of Service via Unbounded Registration TTL in Discovery Responses
- CVE-2026-89158 — PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant...
- CVE-2026-89157 — PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an...
- CVE-2026-88914 — Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser
- CVE-2026-16174 — Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow
- CVE-2026-88035 — Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver
- CVE-2026-85228 — Integer overflow in tensor buffer validation in Deep Java Library