THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-43629 (HIGH 8.1) — llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt

[NVD] CVE-2026-43629 (HIGH 8.1) — llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt

lownvdPublished 2026-08-06

CVE-2026-43629 CVSS: 8.1 HIGH Published: 2026-08-06T22:17:05.917

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt heap memory. Attackers can craft malicious state file

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-43629