CVE-2026-39909
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-416
Utilización después de liberación
Fecha de publicación:
21/08/2026
Última modificación:
21/08/2026
Descripción
*** Pendiente de traducción *** llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced buffers, and reclaiming freed memory with attacker-controlled content. Attackers can send RPC requests to trigger re-execution of stored graphs with dangling pointers, enabling full remote code execution without requiring authentication or user interaction.
Impacto
Puntuación base 4.0
9.20
Gravedad 4.0
CRÍTICA
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA


