Overview
llama.cpp <= b5693 (commit 97f06e9) is vulnerable to a reachable assertion through the gguf_reader::read function. Any llama.cpp binary that loads a GGUF file is affected.
Details
- Vulnerable functions:
gguf_reader::read(line 333) and thegguf_kvconstructor (lines 143/151/161/167) inggml/src/gguf.cpp - Discovery method: libFuzzer
- Minimal trigger file: 28 bytes
- Reproducibility: 100%. When
key_len=0, the empty-key path always executes.
NVD
- CVSS: 7.5 (high) — raised from 5.5 (medium) on NVD re-evaluation. The original analysis assumed local access; NVD re-scored it as remotely reachable.
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CWE: CWE-617 (Reachable Assertion)
- Attack vector: Network (remote)
- Published: 2026-09-01 (NVD)
Patch status
- Fixed — PR #24917 "gguf : reject empty metadata keys" (2026-07-11, commit
d72bfa38f7) rejects empty metadata keys (key_len=0), blocking the root cause. It changesgguf.cppand adds a regression test (test-gguf.cpp).