Null Pointer Dereference in ggml-org Whisper.cpp Affects Local Environments
CVE-2026-10298
Key Information:
- Vendor
Ggml-org
- Status
- Vendor
- CVE Published:
- 1 June 2026
Badges
What is CVE-2026-10298?
A security flaw has been identified in ggml-org's whisper.cpp, specifically in the function whisper_model_load found in the file ggml/src/ggml.c. This vulnerability leads to a null pointer dereference, which can be exploited by malicious actors if they have local access to the system. Although the project was notified early through an issue report, the issue remains unaddressed, making systems running affected versions susceptible to attack. As the exploit has been made public, immediate attention is recommended to mitigate potential security risks.
Affected Version(s)
whisper.cpp 1.8.0
whisper.cpp 1.8.1
whisper.cpp 1.8.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
