CVE-2026-43627
CVE-2026-43627: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.8
High [CVE-2026-43627] Arbitrary Code Execution via Integer Overflow in Memory Allocation
CVE-2026-43627Source published Source updated
llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries. Exploitation requires convincing a user or local process to execute inference workloads using maliciously oversized batch sizing parameters, leading to an arithmetic overflow during memory allocation and subsequent heap corruption. Full impact across Confidentiality, Integrity, and Availability (C:H, I:H, A:H) is possible if local memory…
- Affected products in this advisory
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- To reduce the risk, avoid processing untrusted or malicious input with applications that use the llama.cpp library. Deploying applications that utilize llama.cpp within a sandboxed environment can further limit the potential impact of successful exploitation.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.