CVE-2026-27940 | ggml-org llama.cpp gguf_init_from_file_impl heap-based overflow (b8146 / Nessus ID 302198)
A vulnerability, which was classified as critical, has been found in ggml-org llama.cpp. This affects the function gguf_init_from_file_impl. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is known as CVE-2026-27940. Attacking locally is a requirement. No exploit is available.
To fix this issue, it is recommended to deploy a patch.