Bug 2437911 (CVE-2026-2069) - CVE-2026-2069 llama.cpp: infinite recursion in GBNF grammar via nested repetition
Summary: CVE-2026-2069 llama.cpp: infinite recursion in GBNF grammar via nested repeti...
Keywords:
Status: NEW
Alias: CVE-2026-2069
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2448111
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-09 11:13 UTC by OSIDB Bzimport
Modified: 2026-03-16 17:28 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-02-09 11:13:24 UTC
A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This manipulation causes stack-based buffer overflow. The attack needs to be launched locally. The exploit has been published and may be used. Patch name: 18993. To fix this issue, it is recommended to deploy a patch.


Note You need to log in before you can comment on or make changes to this bug.