PT-2025-29152 · Llama.Cpp · Llama.Cpp

Yuuoniy

·

Published

2025-07-10

·

Updated

2026-03-12

·

CVE-2025-53630

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: llama.cpp (affected versions not specified)
Description: An integer overflow in the gguf init from file impl function within ggml/src/gguf.cpp can lead to a Heap Out-of-Bounds Read/Write.
Recommendations: Update to a version containing commit 26a48ad699d50b6268900062661bd22f3e792579.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-53630
GHSA-VGG9-87G3-85W8
OPENSUSE-SU-2025:15343-1

Affected Products

Llama.Cpp