THREAT OPS › Threat News › [NVD] CVE-2026-70638 (HIGH 7.8) — llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocatio
[NVD] CVE-2026-70638 (HIGH 7.8) — llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocatio
CVE-2026-70638 CVSS: 7.8 HIGH Published: 2026-08-06T22:18:28.633
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers
Indicators of compromise
- CVE-2026-70638cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70638