CVE-2026-34159: llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenti...

Added to the CISA Known Exploited Vulnerabilities catalog on 01 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.8.

llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenticated attacker can read and write arbitrary process memory via crafted GRAPH_COMPUTE messages. Combi...

Required action: Review and patch if applicable to your AI infrastructure.