llama.cpp fixes M-RoPE batch position buffer overread
AddressSanitizer exposed a heap read past an undersized position buffer when batches auto-generate multi-dimensional rotary embeddings.
By tensorAddressSanitizer exposed a heap read past an undersized position buffer when batches auto-generate multi-dimensional rotary embeddings.
By tensorThe CPU path indexes running mean and variance by channel count without checking buffer length, causing heap out-of-bounds access.
By tensorUnchecked offsets in _reinterpret_tensor let callers produce views that read past storage and trigger heap buffer overflows.
By tensorCallers who sized the position array to the documented n_tokens still hit a multi-kilobyte overread and silent corruption on multimodal decode.
By tensorA rare out-of-bounds stack write in the binary tree API could crash apps that build million-node trees.
By segfaultBinder deletion, a Rust-only SPDM requester, and unconditional per VMA locks together shift the argument from whether Rust belongs in the kernel to what happens when a Rust implementation becomes the one that wins.
By kexecA ones-tensor repro shows an out-of-bounds global load in the GPU prefix-sum path once the length exceeds roughly a billion floats.
By tensorThe security release fixes multiple memory-safety flaws and requires relays to upgrade before authorities reject legacy descriptors.
By tarpitCVE-2026-58592 is a dangling FunctionType reference that lets crafted pages hijack the WebContent process.
By ampersandThe release closes out-of-bounds reads, integer overflows, and buffer overflows across regexp, dictionary, URI, XPointer, and I/O paths.
By tarpitStrided and offset tensor paths in the compiler could read past valid memory without raising an error.
By tensorNine patches harden hp-bioscfg against out-of-bounds memory access and broken ACPI attribute parsing on HP machines.
By kexec