Impact
The vulnerability is an out‑of‑bounds read in the log_mel_spectrogram function of whisper.cpp version 1.8.4-58. The flaw allows a local attacker to read memory past the intended buffer boundaries, which could result in the disclosure of sensitive information or a possible crash of the application. No privilege escalation or remote execution is indicated by the current description.
Affected Systems
The affected product is ggml‑org whisper.cpp, specifically the 1.8.4-58 release. No other vendors or product versions are mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 4.8 reflects moderate severity. EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating that it is not actively exploited in the wild. Attack execution requires local access to the system, so the risk is limited to environments where the whisper.cpp binary can be run by an untrusted user. The pull request that fixes the issue is awaiting review, so a patched version is not yet released.
OpenCVE Enrichment