Use-After-Free and Double Free Vulnerability in llama.cpp by ggml-org
CVE-2026-107183
9.2CRITICAL
What is CVE-2026-107183?
The llama.cpp library, prior to version b11393, has a significant vulnerability in the common_chat_peg_mapper::map function, where a use-after-free and double free condition is present. This flaw enables unauthenticated remote attackers to exploit a dangling pointer in current_tool, leading to potential corruption of heap memory. By manipulating a chat_parser in a POST /completion request with a tool-id following a tool-close tag, an attacker can trigger a crash in the llama-server, paving the way for further exploits.
Affected Version(s)
llama.cpp b8227
llama.cpp b11393
