Database/AI/ML frameworks & serving

llama.cpp (`ggml_nbytes`): Integer overflow in the core ggml size calculation
CVSS 7.8CVE-2026-33298AI/ML frameworks & servingcurated
Impact
Integer overflow in the core ggml size calculation
Who can reach it
Customer-supplied model file
What to do
Rebuild past b7824; affects every ggml-based downstream (whisper.cpp, stable-diffusion.cpp)
References
Related entries
- BentoML (`docker.system_packages`): Command injection through the package list fieldCVE-2026-33744 · BentoML (`docker.system_packages`)High
- BentoML (cloud deployment path, setup.sh generation in deployment.py): The March fix that added shlex.quote to theCVE-2026-35043 · BentoML (cloud deployment path, setup.sh generation in deployment.py)High
- SGLang (`replay_request_dump.py`): Insecure `pickle.load()` on a `.pkl` dumpCVE-2026-3989 · SGLang (`replay_request_dump.py`)High
- llama.cpp (`llama_batch_init`): Integer overflow from unchecked multiplicationCVE-2026-43627 · llama.cpp (`llama_batch_init`)High
- HuggingFace transformers: Critical RCE in all versions before 5.3.0CVE-2026-4372 · HuggingFace transformersHigh
- stable-diffusion.cpp: Memory-safety flaw in model loadingCVE-2026-47749 · stable-diffusion.cppHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.