
CVE-2026-70638 (CVSS 7.8): llama.cpp's Android JNI wrapper multiplies sizeof(int) by an attacker value read straight from the GGUF model file — no bounds check, no NULL check. The fix? A rewrite that deleted the function. #llamacpp #Android #LLM https://www.hunt-benito.com/blog/one-multiply-too-many-cve-2026-70638-integer-overflow-in-llamacpps-android-jni-heap-allocation/ https://t.co/KBVNmUaQ4H
Post summary
The post discloses an integer overflow in llama.cpp’s Android JNI wrapper (CVSS 7.8) and notes that the issue is resolved by rewriting/removing the function.
