Bug 2507583 - CVE-2026-17513 whisper-cpp: whisper.cpp: Denial of Service via ftype argument manipulation [fedora-all]
Summary: CVE-2026-17513 whisper-cpp: whisper.cpp: Denial of Service via ftype argument...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: whisper-cpp
Version: rawhide
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Tom.Rix
QA Contact:
URL:
Whiteboard: {"flaws": ["7de412f7-9823-43f7-ba4e-1...
Depends On:
Blocks: CVE-2026-17513
TreeView+ depends on / blocked
 
Reported: 2026-07-27 17:11 UTC by Thibault Guittet
Modified: 2026-07-27 17:11 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Thibault Guittet 2026-07-27 17:11:38 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.


Note You need to log in before you can comment on or make changes to this bug.