Use-After-Free Vulnerability in llama.cpp RPC Server
CVE-2026-39909
9.2CRITICAL
What is CVE-2026-39909?
A use-after-free vulnerability exists in the RPC server's GRAPH_RECOMPUTE handler of llama.cpp prior to version b8585. This flaw allows unauthorized remote attackers to execute arbitrary read and write operations. By manipulating computation graphs, attackers can free referenced buffers and later reclaim the freed memory, substituting it with malicious content. This exploitation enables the execution of arbitrary code remotely without requiring any form of authentication or user intervention, posing significant risks to the security of affected systems.
Affected Version(s)
llama.cpp 0
