Impact
The vulnerability resides in the RPC Server of ggml.cpp, where a manipulated argument can trigger a reachable assertion in ggml-rpc.cpp. This assertion failure causes the server process to terminate, allowing an attacker to disrupt service availability. The flaw is an assertion failure resulting from improper argument validation.
Affected Systems
The affected product is ggml-org llama.cpp, specifically all releases up to and including version 0.4.0. No later version information is provided, so any instance running version 0.4.0 or earlier is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability presents moderate severity. The EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation yet. According to the description, the attack vector is remote, and exploitation would likely result in a denial of service through a server crash.
OpenCVE Enrichment