CVE Feed

    Dashboard / CVE / CVE-2026-70638

    CVE-2026-70638

    llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a malicious model file or JNI call to trigger heap corruption and achieve denial of service or arbitrary code execution on Android applications using the LLaMA-Android binding.

    Published:Aug 6, 2026
    Last Modified:Aug 14, 2026
    EPS:Aug 6, 2026
    EPSS Score:0.00134
    CVSS Score:7.8

    Affected Products

    Vendor
    Ggml
    Product
    Llama.cpp
    Vendor
    Ggml-org
    Product
    Llama.cpp

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High