ggml-org whisper.cpp log_mel_spectrogram out-of-bounds
CVE-2026-17512
4.8MEDIUM
What is CVE-2026-17512?
A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.
Affected Version(s)
whisper.cpp 1.8.4-58
