PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17513 ggml-org CVE debrief

A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. This issue has been publicly disclosed and may impact ggml-org whisper.cpp users with local access. The vulnerability class is related to an assertion that can be triggered by manipulating the ftype argument. The likely operational impact includes potential denial of service or elevation of privileges. However, the source confidence is limited, and defenders should verify affected deployments and review official advisories for specific guidance.

Vendor
ggml-org
Product
whisper.cpp
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Users of ggml-org whisper.cpp 95ea8f9b who require local access to the system should review their deployments for potential exposure. This includes operators, platform administrators, and security teams responsible for vulnerability management.

Technical summary

The vulnerability is located in the ggml_ftype_to_ggml_type function of the ggml/src/ggml.c file in the ggml-org whisper.cpp 95ea8f9b project. An attacker with local access can manipulate the ftype argument to trigger a reachable assertion. The CVSS score of 1.9 indicates a low severity vulnerability. The vulnerability is related to the ggml_ftype_to_ggml_type function, which does not properly handle certain input values. This can lead to a reachable assertion, potentially causing a denial of service. Defenders should focus on restricting local access to ggml-org whisper.cpp installations and monitoring for potential exploitation attempts.

Defensive priority

Low priority due to local attack requirement and low CVSS score of 1.9.

Recommended defensive actions

  • Inventory ggml-org whisper.cpp 95ea8f9b installations for potential exposure
  • Restrict local access to ggml-org whisper.cpp 95ea8f9b installations
  • Monitor ggml-org whisper.cpp 95ea8f9b for official remediation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The project was informed of the problem early through an issue report but has not responded yet. The CVE record was published on 2026-07-27T14:16:52.073Z and has not been modified since. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T14:16:52.073Z and has not been modified since.