CVE-2024-42477: Ggml Llama.cpp

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

llama.cpp provides LLM inference in C/C++. The unsafe `type` member in the `rpc_tensor` structure can cause `global-buffer-overflow`. This vulnerability may lead to memory data leakage. The vulnerability is fixed in b3561.

Affected products

  • Ggml Llama.cpp: before b3561 (fixed in b3561)

Published 2024-08-12. Last modified 2026-06-17.