CVE-2025-49847 describes a critical buffer overflow vulnerability in llama.cpp, affecting versions prior to b5662, where a malicious GGUF model vocabulary can trigger memory corruption during vocabulary loading. This flaw, rated 8.8 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), allows an attacker to achieve arbitrary memory corruption and potentially remote code execution by bypassing a length check due to an integer overflow. While the vulnerability is severe, requiring user interaction to load a malicious model, there is currently no evidence of active exploitation, public exploit code, or significant community discussion. The issue has been patched in version b5662.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< b5662CPE matchmatch criteria | cpe:2.3:a:ggml:llama.cpp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.