CVE-2026-33298: llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting ...
Added to the CISA Known Exploited Vulnerabilities catalog on 24 Mar 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.8.
llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor dimensions. This causes `ggml_nbytes` to return a significantly sma...
Required action: Review and patch if applicable to your AI infrastructure.