Null Pointer Dereference Vulnerability in ggml-RPC Server by ggml-org
CVE-2026-78148
6.9MEDIUM
What is CVE-2026-78148?
A vulnerability exists in the ggml-RPC Server of the ggml-org project, specifically in the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp. This flaw can be exploited to cause a null pointer dereference, which results in a potential denial of service. The vulnerability can be triggered remotely, allowing attackers to manipulate the server and disrupt its operations. A fix for this issue is currently pending acceptance, emphasizing the importance of timely updates to maintain security.
Affected Version(s)
llama.cpp bec4772f6
