Source: llama.cpp
Version: 10108+dfsg1-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for llama.cpp.

CVE-2026-17500[0]:
| A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0.
| This affects the function _visit_pattern of the file common/json-
| schema-to-grammar.cpp. The manipulation results in null pointer
| dereference. The attack can be launched remotely. The pull request
| to fix this issue awaits acceptance.


CVE-2026-17501[1]:
| A flaw has been found in ggml-org llama.cpp e15efe0. This
| vulnerability affects the function transform of the file
| common/json-schema-to-grammar.cpp of the component JSON-Schema-to-
| GBNF Conversion. This manipulation causes uncontrolled recursion.
| The attack may be initiated remotely. The pull request to fix this
| issue awaits acceptance.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-17500
    https://www.cve.org/CVERecord?id=CVE-2026-17500
[1] https://security-tracker.debian.org/tracker/CVE-2026-17501
    https://www.cve.org/CVERecord?id=CVE-2026-17501

Regards,
Salvatore

Reply via email to