CVE-2025-49847: llama.cpp Vulnerable to Buffer Overflow via Malicious GGUF Model

Published Jun 17, 2025
·
Updated

llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabulary can trigger a buffer overflow in llama.cpp’s vocabulary‐loading code. Specifically, the helper trycopy in llama.cpp/src/vocab.cpp: llamavocab::impl::tokentopiece() casts a very large sizet token length into an int32t, causing the length check (if (length < (int32t)size)) to be bypassed. As a result, memcpy is still called with that oversized size, letting a malicious model overwrite memory beyond the intended buffer. This can lead to arbitrary memory corruption and potential code execution. This issue has been patched in version b5662.

Affected Software

2 affected components
Llama.cpp llama.cpp<b5662
ggml llama.cpp<b5662

Event History

Jun 17, 2025
CVE Published
via MITRE·08:04 PM
Data Sourced
via MITRE·08:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-49847?

CVE-2025-49847 has been classified as a high severity vulnerability due to the potential for buffer overflow exploitation.

2

How do I fix CVE-2025-49847?

To mitigate CVE-2025-49847, update to llama.cpp version b5662 or later as it resolves the buffer overflow issue.

3

What type of vulnerability is CVE-2025-49847?

CVE-2025-49847 is a buffer overflow vulnerability occurring during the loading of attacker-supplied GGUF model vocabulary.

4

What software is affected by CVE-2025-49847?

CVE-2025-49847 affects llama.cpp versions prior to b5662.

5

Can CVE-2025-49847 be exploited remotely?

Yes, CVE-2025-49847 can be exploited remotely if an attacker supplies a malicious GGUF model vocabulary.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203