Null Pointer Dereference Vulnerability in LLaMA-Android by ggml-org
CVE-2026-70639

6.8MEDIUM

Key Information:

Vendor

Ggml-org

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-70639?

The LLaMA-Android JNI wrapper in specific builds of llama.cpp is susceptible to a null pointer dereference. This vulnerability occurs within the bench_1model() function, where the model context pointer is not adequately validated prior to dereferencing. Malicious users can exploit this weakness by supplying a malformed, corrupt, or truncated model file. This can lead to a null context scenario, resulting in a SIGSEGV crash that abruptly terminates the Android application, thereby creating a denial of service condition.

Affected Version(s)

llama.cpp b1886

llama.cpp 0.9.0 <= 0.17.1

llama.cpp 5c0d18881e0e9794c96b2602736b758bac9d9388

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vladimir Tokarev (@G1ND1L4) - Vulnerability Research Tech Lead, Cyera
Ofek Itach (@ofekitach) - Security Research Team Lead, Cyera
.