CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-43627

highCVSS 7.8covered by 1 sourcefirst seen 2026-08-06
llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.

⚡ Watch CVE-2026-43627

Get an email if CVE-2026-43627 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-43627

CVE.org record

Embed the live status

CVE-2026-43627 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-43627 status](https://www.csirts.com/badge/CVE-2026-43627)](https://www.csirts.com/cve/CVE-2026-43627)