UBUNTU-CVE-2026-86317

Source
https://ubuntu.com/security/CVE-2026-86317
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-86317.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-86317
Upstream
Published
2026-09-07T15:17:00Z
Modified
2026-09-16T14:03:45Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation of the argument ne results in reachable assertion. The attack is possible to be carried out remotely. The reported GitHub issue was closed automatically due to inactivity.

References

Affected packages

Ubuntu:26.04:LTS / llama.cpp

Package

Name
llama.cpp
Purl
pkg:deb/ubuntu/llama.cpp?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
5882+dfsg-2
8064+dfsg-1ubuntu1
8681+dfsg-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "libllama0",
            "binary_version":  "8681+dfsg-1"
        },
        {
            "binary_name":  "llama.cpp",
            "binary_version":  "8681+dfsg-1"
        },
        {
            "binary_name":  "llama.cpp-examples",
            "binary_version":  "8681+dfsg-1"
        },
        {
            "binary_name":  "llama.cpp-tests",
            "binary_version":  "8681+dfsg-1"
        },
        {
            "binary_name":  "llama.cpp-tools",
            "binary_version":  "8681+dfsg-1"
        },
        {
            "binary_name":  "llama.cpp-tools-extra",
            "binary_version":  "8681+dfsg-1"
        },
        {
            "binary_name":  "python3-gguf",
            "binary_version":  "8681+dfsg-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-86317.json"