What is CVE-2026-17513?
A reachable assertion vulnerability has been identified in the ggml_ftype_to_ggml_type function located in ggml/src/ggml.c of ggml-org whisper.cpp version 95ea8f9b. This local vulnerability is triggered by manipulating the 'ftype' argument, potentially leading to a denial of service. The project has been notified early, and users are advised to apply the necessary updates.
Azərbaycanca: ggml-org whisper.cpp 95ea8f9b versiyasında ggml/src/ggml.c faylında yerləşən ggml_ftype_to_ggml_type funksiyasında reachable assertion zəifliyi aşkarlanıb. Bu zəiflik yerli giriş tələb edir və ftype arqumentinin manipulyasiyası nəticəsində xidmət rəddi (denial of service) vəziyyətinə səbəb ola bilər. Layihəyə erkən məlumat verilib, istifadəçilərə yeniləmələri tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: ggml-org
FAQ2
Which product and version are affected by CVE-2026-17513?
This vulnerability affects version 95ea8f9b of the ggml-org whisper.cpp project.
What type of access does an attacker need to exploit CVE-2026-17513?
Exploiting this vulnerability requires local access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.