CVE-2026-27940

llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread() writes 528+ bytes of attacker-controlled data past the buffer boundary. This is a bypass of a similar bug in the same file - CVE-2025-53630, but the fix overlooked some areas. This vulnerability is fixed in b8146.
Configurations

No configuration.

History

12 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 17:16

Updated : 2026-03-12 21:07


NVD link : CVE-2026-27940

Mitre link : CVE-2026-27940

CVE.ORG link : CVE-2026-27940


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow

CWE-190

Integer Overflow or Wraparound