- CVSS
- HIGH · 8.1v3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- 2026-08-21
- Weakness
- CWE-416
- Source
- nvd.nist.gov/vuln/detail/CVE-2026-39909
Description
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server’s GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by storing a computation graph, freeing referenced buffers, and reclaiming freed memory with attacker-controlled content. Attackers can send RPC requests to trigger re-execution of stored graphs with dangling pointers, enabling full remote code execution without requiring authentication or user interaction.
References
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2026-39909 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.