THREAT OPS › Threat News › [NVD] CVE-2026-43629 (HIGH 8.1) — llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt
[NVD] CVE-2026-43629 (HIGH 8.1) — llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt
CVE-2026-43629 CVSS: 8.1 HIGH Published: 2026-08-06T22:17:05.917
llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt heap memory. Attackers can craft malicious state file
Indicators of compromise
- CVE-2026-43629cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-43629