Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 07 Aug 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ggml-org
Ggml-org llama.cpp |
|
| Vendors & Products |
Ggml-org
Ggml-org llama.cpp |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by performing heap spray with attacker-controlled data containing a fake vtable to hijack the vtable pointer at offset +0x30, causing llama_batch_allocr::clear() to dereference arbitrary memory and achieve remote code execution. | |
| Title | llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cpp | |
| Weaknesses | CWE-362 CWE-476 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-06T15:47:17.244Z
Reserved: 2026-08-04T20:17:18.298Z
Link: CVE-2026-70640
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T02:00:06Z