Description
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
Published: 2026-10-07
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A use‑after‑free in the common_chat_peg_mapper::map function of llama.cpp allows an attacker who can send a crafted POST /completion request to the llama‑server to corrupt heap memory via a dangling current_tool pointer. By emitting a tool‑id after a tool‑close tag in the chat_parser payload, the attacker can trigger a heap write primitive that may lead to arbitrary code execution or a denial‑of‑service crash.

Affected Systems

Any installation of ggml‑org’s llama.cpp that predates commit b11393 is vulnerable. The flaw resides in the code path exercised by the server’s chat parsing logic and does not affect later releases that incorporate the fix.

Risk and Exploitability

The CVSS score of 9.2 indicates a high severity vulnerability. Although an EPSS score is not available and the issue is not listed in the CISA KEV catalog, the vulnerability is exploitable over an unauthenticated remote connection that can transmit a malicious payload to the server. Successful exploitation could compromise confidentiality, integrity, or availability of the affected system.

Generated by OpenCVE AI on October 7, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a version of llama.cpp that is newer than b11393, which contains the fix for the use‑after‑free.
  • If an upgrade cannot be performed immediately, hard‑enforce strict validation of the chat_parser payload for the sequence of tool‑id and tool‑close tags, or block POST /completion requests that contain a tool‑id following a tool‑close tag.
  • Configure server monitoring to alert on repeated malformed POST /completion requests, and restart the service upon detecting such activity.

Generated by OpenCVE AI on October 7, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
Title llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser
First Time appeared Ggml
Ggml llama.cpp
Weaknesses CWE-416
CPEs cpe:2.3:a:ggml:llama.cpp:*:*:*:*:*:*:*:*
Vendors & Products Ggml
Ggml llama.cpp
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-07T14:37:12.658Z

Reserved: 2026-10-07T13:04:03.727Z

Link: CVE-2026-107183

cve-icon Vulnrichment

Updated: 2026-10-07T14:37:05.670Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T14:17:09.003

Modified: 2026-10-07T15:57:20.793

Link: CVE-2026-107183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T16:15:18Z

Weaknesses