What is CVE-2026-17512?
A local out-of-bounds read vulnerability has been identified in the `log_mel_spectrogram` function within `src/whisper.cpp` of ggml-org whisper.cpp version 1.8.4-58. Mitigation involves applying the pending fix once accepted or implementing restrictive measures per organizational security policy.
Azərbaycanca: ggml-org whisper.cpp 1.8.4-58 versiyasında `src/whisper.cpp` faylındakı `log_mel_spectrogram` funksiyasında lokal `out-of-bounds read` zəifliyi aşkarlanıb. Təhlükəsizlik tədbiri olaraq, müvafiq düzəlişin tətbiq olunmasını gözləmək və ya təşkilatın təhlükəsizlik siyasətinə uyğun məhdudlaşdırıcı tədbirlər görmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
In which version of whisper.cpp was the CVE-2026-17512 vulnerability discovered?
The CVE-2026-17512 vulnerability was discovered in version 1.8.4-58 of ggml-org whisper.cpp.
What temporary mitigation measures are recommended for CVE-2026-17512?
The primary recommendation is to await the application of the pending fix. Additionally, implementing restrictive measures in accordance with organizational security policy is advised.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.