Bug 2512314 (CVE-2026-43631)
| Summary: | CVE-2026-43631 llama.cpp: llama.cpp: Remote code execution via use-after-free vulnerability in llama-server | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | bbrownin |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in llama.cpp. This use-after-free vulnerability in the llama-server component, specifically within the vocab pointer when the `--sleep-idle-seconds` feature is enabled, allows unauthenticated remote attackers to execute arbitrary code. Attackers can exploit this by sending requests while the server transitions to sleep mode, leading to concurrent worker threads to dereference a freed memory region. This can be reclaimed with attacker-controlled data, resulting in remote code execution.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2514596 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-06 22:29:04 UTC
|