CVE-2026-70638 is an integer overflow vulnerability in ggml-org llama.cpp affecting builds b1886 through b7445 and semantic versions 0.9.0 through 0.17.1. The flaw is in the LLaMA-Android JNI wrapper's new_1batch() function, which multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max value without validating for arithmetic overflow. If the multiplication wraps, the code allocates an undersized heap buffer and subsequently operates on it as though it were correctly sized, creating a heap corruption condition. The vulnerable input can be introduced through a crafted JNI call or a malicious model file processed by an Android application using the LLaMA-Android binding. The resulting memory corruption can crash the application or enable arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept set for CVE-2026-70638, an integer overflow in llama.cpp Android JNI batch allocation logic. It is not a full weaponized exploit; instead it demonstrates exploitability conditions and attacker control over the vulnerable multiplicands used in unchecked malloc size calculations. Repository structure: - README.md: documents the vulnerability, affected versions, usage, and references. - overflow_demo.c: standalone arithmetic reproducer showing how sizeof(llama_seq_id) * n_seq_max wraps on 32-bit Android (armeabi-v7a), causing an undersized allocation relative to intended write size. It explicitly avoids performing an out-of-bounds write. - craft_gguf.py: generates a minimal metadata-only GGUF file with attacker-controlled llama.embedding_length. This demonstrates the file-based delivery vector where untrusted model metadata influences the embd parameter consumed by the vulnerable JNI function. - hook_new_batch.js: Frida instrumentation script for live-device research. It locates the JNI export Java_android_llama_cpp_LLamaAndroid_new_1batch in likely native libraries, hooks it, logs n_tokens/embd/n_seq_max, and can override them to force the overflow path during testing. Main exploit capabilities: - Demonstrates the vulnerable allocation arithmetic and 32-bit wraparound behavior. - Crafts a malicious GGUF artifact to supply attacker-controlled metadata into the vulnerable code path. - Hooks the live JNI boundary to inspect and optionally modify exploit-relevant parameters. Attack surface and purpose: - Primary vector is file-based/local: a malicious GGUF model file influences metadata parsed by an affected Android llama.cpp integration. - Secondary vector is local dynamic instrumentation via Frida for research validation. - The PoC targets Android JNI bindings in llama.cpp builds b1886-b7445; practical heap corruption is emphasized for 32-bit ABIs, while 64-bit behavior is described as large allocation failure/DoS rather than wraparound heap corruption. Overall, this is a credible research PoC repository focused on demonstrating input control and arithmetic conditions behind the vulnerability, not on delivering a post-exploitation payload or automated compromise chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A replacement CVE identifier mentioned only in background context; no vulnerability details are provided in this article.
An integer overflow vulnerability in the LLaMA-Android JNI wrapper of ggml-org llama.cpp that can lead to heap corruption, denial of service, or arbitrary code execution in Android applications using the LLaMA-Android binding.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.