CVE-2026-70638 | ggml-org llama.cpp up to 0.17.1/b7445 LLaMA-Android JNI Wrapper new_1batch n_seq_max integer overflow

SecurityVulns

A vulnerability, which was classified as critical, has been found in ggml-org llama.cpp up to 0.17.1/b7445. Affected is the function new_1batch of the component LLaMA-Android JNI Wrapper. The manipulation of the argument n_seq_max leads to integer overflow.

This vulnerability is documented as CVE-2026-70638. The attack can be initiated remotely. There is not any exploit available.

To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More