CVE-2026-2069
A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This manipulation causes stack-based buffer overflow. The attack needs to be launched locally. The exploit has been published and may be used. Patch name: 18993. To fix this issue, it is recommended to deploy a patch.
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-02-06 22:16:12
Güncelleme
2026-02-09 16:08:55
Source Identifier
cna@vuldb.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/ggml-org/llama.cpp/
https://github.com/ggml-org/llama.cpp/issues/18988
https://github.com/ggml-org/llama.cpp/issues/18988#event-4426704865
https://github.com/ggml-org/llama.cpp/pull/18993
https://github.com/user-attachments/files/24761101/poc.zip
https://vuldb.com/?ctiid.344636
https://vuldb.com/?id.344636
https://vuldb.com/?submit.745263