CVE-2026-43629 PUBLISHED

llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore

Assigner: VulnCheck
Reserved: 01.05.2026 Published: 06.08.2026 Updated: 06.08.2026

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt heap memory. Attackers can craft malicious state files where cell_count multiplication overflows or exceeds tensor buffer allocation to write attacker-controlled bytes past buffer boundaries, potentially resulting in heap metadata corruption, model weight corruption, or arbitrary code execution via function pointer overwrite.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor ggml-org
Product llama.cpp
Versions Default: affected
  • affected from b4882 to b9058 (incl.)
  • affected from 0.16.1 to 0.17.1 (incl.)

Credits

  • Vladimir Tokarev (@G1ND1L4) - Vulnerability Research Tech Lead, Cyera finder
  • Ofek Itach (@ofekitach) - Security Research Team Lead, Cyera finder

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE
  • CWE-190 Integer Overflow or Wraparound CWE