216.73.217.22

CVE-2026-33298

· Published 24/03/2026 01:17 · Modified 24/03/2026 15:53

Labels: CVE-2026-33298 2026-03-24CVE-2026-33298CWE-122[email protected]

Essential information

Published
24/03/2026 01:17
Modified
24/03/2026 15:53
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This causes `ggml_nbytes` to return a significantly smaller size than required (e.g., 4MB instead of Exabytes), leading to a heap-based buffer overflow when the application subsequently processes the tensor. This vulnerability allows potential Remote Code Execution (RCE) via memory corruption. b7824 contains a fix.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
llama / llama cpp cpe:2.3:a:llama:llama_cpp:b7824:*:*:*:*:*:*:*

References