CVE-2026-70638Patch(ggml / llama.cpp)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ggml llama.cpp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a malicious model file or JNI call to trigger heap corruption and achieve denial of service or arbitrary code execution on Android applications using the LLaMA-Android binding.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • llama.cpp

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
llama.cpp

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-07: 1Patch / Workaround · 2026-08-07: 1Technical Details · 2026-08-07: 108-07
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Hunt-Benito@HB_CyberSec
    Patch

    CVE-2026-70638 (CVSS 7.8): llama.cpp's Android JNI wrapper multiplies sizeof(int) by an attacker value read straight from the GGUF model file — no bounds check, no NULL check. The fix? A rewrite that deleted the function. #llamacpp #Android #LLM https://www.hunt-benito.com/blog/one-multiply-too-many-cve-2026-70638-integer-overflow-in-llamacpps-android-jni-heap-allocation/ https://t.co/KBVNmUaQ4H

    Post summary

    The post discloses an integer overflow in llama.cpp’s Android JNI wrapper (CVSS 7.8) and notes that the issue is resolved by rewriting/removing the function.

    0002199
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appggmlllama.cpp---

Explore more