DEBIAN-CVE-2026-43628

Source
https://security-tracker.debian.org/tracker/CVE-2026-43628
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-43628.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-43628
Upstream
  • CVE-2026-43628
Published
2026-08-06T22:17:05Z
Modified
2026-09-14T17:03:39Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_allowed_length set to INT32_MIN to the /v1/completions or /v1/chat/completions endpoints. Attackers can exploit this vulnerability to crash the server with SIGSEGV causing denial of service for all connected users, or corrupt token sampling probabilities by reading garbage values from memory before the allocated buffer.

References

Affected packages

Debian:14 / llama.cpp

Package

Name
llama.cpp
Purl
pkg:deb/debian/llama.cpp?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
5151+dfsg-1~exp2
5151+dfsg-1~exp3
5318+dfsg-1
5318+dfsg-2
5713+dfsg-1
5760+dfsg-1
5760+dfsg-2
5760+dfsg-3
5760+dfsg-4
5882+dfsg-1
5882+dfsg-2
5882+dfsg-3~exp1
5882+dfsg-3~exp2
5882+dfsg-3~exp3
5882+dfsg-3
5882+dfsg-4
6641+dfsg-1
6641+dfsg-2
6641+dfsg-3
7593+dfsg-1
7593+dfsg-2
7593+dfsg-3
7965+dfsg-1
8064+dfsg-1
8064+dfsg-2
8461+dfsg-1
8611+dfsg-1
8681+dfsg-1
8870+dfsg-1
8941+dfsg-1
9009+dfsg-1
9071+dfsg-1
9190+dfsg-1
9413+dfsg-1
9555+dfsg-1
9601+dfsg-1
9721+dfsg-1
9895+dfsg-1
9895+dfsg-2
9895+dfsg-3
9951+dfsg-1
9951+dfsg-2
9951+dfsg-3
10108+dfsg-1
10108+dfsg1-1
10108+dfsg1-2
10192+dfsg-1
10192+dfsg-2~exp1
10192+dfsg-2
10271+dfsg-1
10344+dfsg-1
10438+dfsg-1
1:0.*
1:0.1.2+dfsg-1~exp1
1:0.2.0+dfsg1-1~exp1
1:0.2.0+dfsg1-1
1:0.4.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-43628.json"