{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/ggerganov/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-43629"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["llama.cpp (b4882-b9058)","llama.cpp (b1886-b7445)","llama.cpp"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ggerganov"],"content_html":"\u003cp\u003eThe llama.cpp project is affected by a heap buffer overflow vulnerability, identified as CVE-2026-43629, impacting builds from b4882 through b9058. The issue resides in the state_read_data() function, which is responsible for restoring the Key-Value (KV) cache state. During this process, the application performs size calculations for memory allocation without sufficient overflow checks. Specifically, the multiplication of the cell_count can result in an integer overflow, leading to an undersized tensor buffer allocation. An attacker who can write files to the configured slot_save_path directory can provide a crafted state file to trigger this overflow, writing arbitrary data beyond the allocated buffer boundaries. This allows for heap metadata corruption, model weight tampering, or arbitrary code execution through the overwriting of function pointers in memory.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability in environments utilizing llama.cpp for model inference allows local attackers with filesystem access to the application's storage paths to achieve code execution under the security context of the llama.cpp process. This poses a significant risk to servers hosting local LLM inference services where users or secondary processes have permissions to drop files into the llama.cpp working directory.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all llama.cpp installations currently running builds between b4882 and b9058 to build b9059 or later immediately.\u003c/li\u003e\n\u003cli\u003eRestrict write access to the directory designated for slot_save_path to only authorized users or service accounts to prevent the placement of malicious state files.\u003c/li\u003e\n\u003cli\u003eAudit filesystem permissions for all directories used by llama.cpp to ensure least privilege is applied to input/output paths.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-07T01:30:06Z","date_published":"2026-08-06T23:30:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-llama-cpp-heap-overflow/","summary":"A heap buffer overflow vulnerability in llama.cpp builds b4882 through b9058 allows attackers with write access to the slot_save_path directory to achieve arbitrary code execution via malicious KV cache state files.","title":"Heap Buffer Overflow in llama.cpp KV Cache Restoration","url":"https://feed.craftedsignal.io/briefs/2026-08-llama-cpp-heap-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Ggerganov","version":"https://jsonfeed.org/version/1.1"}