Out-of-Bounds Read in ggml-org Whisper.cpp Product
CVE-2026-17512
4.8MEDIUM
What is CVE-2026-17512?
A local vulnerability has been identified in the ggml-org Whisper.cpp version 1.8.4-58, specifically within the log_mel_spectrogram function located in src/whisper.cpp. This issue allows for an out-of-bounds read condition, which could be exploited by an attacker with local access. A pull request is already in process for remediation of this vulnerability.
Affected Version(s)
whisper.cpp 1.8.4-58
