CVE-2026-21869Patch(ggml / llama.cpp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ggml llama.cpp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input in the llama.cpp server's completion endpoints without validation to ensure it's non-negative. When a negative value is supplied and the context fills up, llama_memory_seq_rm/add receives a reversed range and negative offset, causing out-of-bounds memory writes in the token evaluation loop. This deterministic memory corruption can crash the process or enable remote code execution (RCE). There is no fix at the time of publication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • llama.cpp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-24); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
llama.cpp

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-24: 1Mentions · 2026-06-08: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-04-24: 1Technical Details · 2026-06-08: 104-2406-08
Signal classification1 categories
Patch
2100.0%
Full discourse2 posts
  • Jesse LaRose@jesselarose
    Patch

    Looking at the n_discard CVE again ... yeah, the part I didn't say out loud yet. CVE-2026-21869 patched the negative case for this same parameter. Floor clamped. Ceiling left open. Our find is the upper-bound the original fix didn't cover — same vector, same code path, sender-controlled, still crashes. Incomplete-fix sibling is a real bug class. The patch closes one direction of a bound. The opposite direction stays open. Researchers move on. The pattern repeats. What our auditor surfaces: missing ceilings on sinks where a floor exists. Floor-only clamps read as guard-nearby-but-asymmetric. The candidate falls out. Verify by hand or by cascade. Crash falls out from there. Dynamically confirmed 2026-06-05 on Spark2 (aarch64, --context-shift). Fix is one line: n_discard = std::min(n_discard, n_left). Closes both the resize underflow and the int overflow in one bound. PR queued behind upstream's new-contributor cap. Respect to whoever shipped the original — they closed half. That's the part worth saying first.

    Post summary

    The post highlights that the initial patch for CVE‑2026‑21869 only addressed one direction of a bounds overflow, and presents a one‑line fix that closes both the resize underflow and integer overflow.

    0001035
    126 followersView on X
  • RazzReport@RazzReport
    Patch

    ggml-org/llama.cpp patched a critical heap overflow vulnerability (CVE-2026-21869) and added Hexagon processor optimizations. Crucial for securing edge deployments and expanding hardware support.

    Post summary

    The text announces that the ggml-org/llama.cpp project has released a patch for CVE-2026-21869, which is a critical heap‑overflow vulnerability, thereby improving security for edge deployments.

    1000044
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appggmlllama.cpp---

Explore more