<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Llama.cpp (&lt; B11393) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/llama.cpp--b11393/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 14:37:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/llama.cpp--b11393/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Heap Memory Corruption in llama.cpp via CVE-2026-107183</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107183/</link><pubDate>Wed, 07 Oct 2026 14:37:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107183/</guid><description>An unauthenticated remote attacker can trigger a use-after-free or double-free condition in llama.cpp version b11393 or earlier by sending a malformed POST /completion request to achieve memory corruption.</description><content:encoded><![CDATA[<p>CVE-2026-107183 identifies a critical memory safety vulnerability within llama.cpp prior to build b11393. The flaw exists in the common_chat_peg_mapper::map function, which handles the parsing of chat interactions. An unauthenticated remote attacker can exploit this vulnerability by submitting a specifically crafted POST request to the /completion endpoint of the llama-server component. By inserting a tool-id tag immediately following a tool-close tag, an attacker triggers an invalid memory state involving a dangling current_tool pointer. This condition results in either a double-free or use-after-free error. Successful exploitation allows for the corruption of heap memory, which can lead to application crashes, denial of service, or the creation of a heap write primitive that may enable remote code execution.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects the llama-server component, which is frequently deployed in local and containerized environments to serve large language models. Successful exploitation permits unauthenticated attackers to cause service instability and potential remote code execution, compromising the host system or container environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all instances of llama.cpp to build b11393 or later immediately to address the underlying memory management defect in common_chat_peg_mapper::map.</li>
<li>Implement network access controls to restrict access to the /completion endpoint of llama-server, ensuring that only trusted internal services can reach the API.</li>
<li>Deploy WAF or reverse-proxy rules to inspect incoming POST requests to /completion, specifically flagging payloads that contain consecutive tool-id tags following tool-close tags or irregular chat syntax.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>webserver</category></item></channel></rss>