PatchSiren cyber security CVE debrief
CVE-2026-86317 ggml-org CVE debrief
A vulnerability was detected in ggml-org llama.cpp up to 0.4.0, impacting the rpc_server::deserialize_tensor function in ggml/src/ggml-rpc/ggml-rpc.cpp of the RPC Server component. This results in a reachable assertion through manipulation of the argument ne. The attack can be carried out remotely. Defenders should assess exposure and verify configurations. The CVE record and associated details provide limited information, suggesting a need for further verification of affected versions and potential impact.
- Vendor
- ggml-org
- Product
- llama.cpp
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for ggml-org llama.cpp deployments should assess exposure and verify configurations. They should prioritize verifying ggml-org llama.cpp versions and configurations, assess exposure based on RPC Server component usage, and monitor for potential manipulation of the argument ne to prevent exploitation and reachable assertion. Defenders should also review compensating controls for exposed systems and track exceptions.
Why it matters
Defenders should prioritize verifying ggml-org llama.cpp versions and configurations, assess exposure based on RPC Server component usage, and monitor for potential manipulation of the argument ne to prevent exploitation and reachable assertion.
- Verify ggml-org llama.cpp versions and configurations to prevent potential manipulation of the argument ne
- Assess exposure based on RPC Server component usage to prevent reachable assertion
- Monitor for potential manipulation of the argument ne to prevent exploitation
Technical summary
The vulnerability impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server in ggml-org llama.cpp up to 0.4.0. Performing a manipulation of the argument ne results in reachable assertion. The attack is possible to be carried out remotely. Defenders should prioritize verifying the affected versions and configurations of ggml-org llama.cpp in their environment, and assess exposure based on the RPC Server component usage. The reported GitHub issue was closed automatically due to inactivity.
Defensive priority
Defenders should prioritize verifying the affected versions and configurations of ggml-org llama.cpp in their environment, and assess exposure based on the RPC Server component usage.
Recommended defensive actions
- Verify ggml-org llama.cpp versions and configurations in the environment
- Assess exposure based on RPC Server component usage
- Monitor for potential manipulation of the argument ne
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the affected versions, exploitation scope, and potential impact. Evidence is limited to the reported GitHub issue, which was closed automatically due to inactivity. Defenders should verify ggml-org llama.cpp versions and configurations, assess exposure based on RPC Server component usage, and monitor for potential manipulation of the argument ne.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86317 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86317
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86317 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86317
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ggml-org/llama.cpp/
-
Source reference
Unverified legacy reference
URL: https://github.com/ggml-org/llama.cpp/issues/25288
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-86317
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/908271
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399508
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399508/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.