Use-After-Free Vulnerability in Llama.cpp Affecting Server Configurations
CVE-2026-43631
9.2CRITICAL
What is CVE-2026-43631?
A use-after-free vulnerability exists in the vocab pointer of the llama-server when the --sleep-idle-seconds feature is enabled. This flaw allows unauthenticated remote attackers to execute arbitrary code against affected endpoints. By sending specific requests during the server's sleep mode transition, attackers can cause worker threads to dereference a freed vocab pointer. The freed pointer can potentially be reclaimed with attacker-controlled data, which leads to unauthorized remote code execution, posing significant risks to system integrity. Mitigation strategies are recommended to protect against potential exploits.
Affected Version(s)
llama.cpp b7492
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vladimir Tokarev (@G1ND1L4) - Vulnerability Research Tech Lead, Cyera
Ofek Itach (@ofekitach) - Security Research Team Lead, Cyera
