CVE-2026-33298: llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting ...

Added to the CISA Known Exploited Vulnerabilities catalog on 24 Mar 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.8.

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This causes `ggml_nbytes` to return a significantly sma...

Required action: Review and patch if applicable to your AI infrastructure.