Database/AI/ML frameworks & serving

llama.cpp ggml RPC server: null pointer dereference in graph_compute kills the GPU worker
Impact
A crafted graph_compute request makes rpc_server dereference a null pointer and terminate the process. The supplied CVSS vector claims availability impact only (VC:N/VI:N/VA:L), so this is a denial of service rather than a data-exposure or integrity issue. On a pooled deployment each crash drops that worker's shard of the model, and because the request needs no authentication a client can loop it - the GPUs sit idle behind a supervisor that keeps restarting a process that keeps dying. Cost is wasted accelerator time and failed inference requests, not a node drain.
Who can reach it
Network, unauthenticated. Any client able to reach the ggml rpc-server port; the server does not authenticate its callers.
What to do
No fixed release exists - the upstream pull request (#25670) is open and awaiting acceptance. Restrict the rpc-server port so only the coordinating process can reach it, keep the worker under a supervisor so a crash restarts cleanly, and track PR #25670 for the fix. Once it merges, adopting it is a binary update and a worker restart, not a node reboot.
References
Related entries
- BentoML: SSRF filter misses 100.64.0.0/10, so serving pods fetch from internal CGNAT hostsCVE-2026-78205 · BentoML make_safe_connect (SSRF address filter, RFC 6598 range)Medium
- vLLM: DeepStream backend misclassification skips pixel limits and lets unauthenticated video exhaust GPU decodeCVE-2026-78684 · vLLM (DeepStream GPU decode path, pixel-limit enforcement)Medium
- llama.cpp RPC server: crafted tensor dimensions hit a reachable assertion and abort the processCVE-2026-86317 · llama.cpp RPC server (rpc_server::deserialize_tensor in ggml/src/ggml-rpc/ggml-rpc.cpp)Medium
- vLLM: audio extracted from video input ignores decode size and duration limitsCVE-2026-90554 · vLLM (NanoNemotronVL audio-from-video extraction, _extract_audio_from_videos)Medium
- vLLM: unvalidated MoRIIO ack fields let a remote client exhaust resources on a serving nodeCVE-2026-92220 · vLLM MoRIIO KV-transfer connector (acknowledgement handler)Medium
- vLLM: rejected prefill requests leak Mooncake transfer placeholders, stalling valid requestsCVE-2026-94625 · vLLM MooncakeConnector (KV transfer placeholder reclamation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.