CVE-2026-27940 identifies an integer overflow vulnerability in `llama.cpp`'s `gguf_init_from_file_impl()` function, affecting versions prior to b8146. This flaw results in an undersized heap allocation, enabling a subsequent `fread()` operation to write over 528 bytes of attacker-controlled data past the buffer boundary. Rated 7.8 HIGH, the vulnerability has a local attack vector requiring user interaction but low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are public exploit codes available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< b8146CPE matchmatch criteria | cpe:2.3:a:ggml:llama.cpp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.