CVE-2024-42478: Ggml Llama.cpp
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address reading. This vulnerability is fixed in b3561.
Affected products
- Ggml Llama.cpp: before b3561 (fixed in b3561)
Published 2024-08-12. Last modified 2026-06-17.