Netskope Threat Labs

FILE-OTHER Heap out-of-bounds read,write in llama.cpp attempted

IPS-CFWIPS-SWG

1 SID: 170176

Detects model files exploiting CVE-2025-53630, heap memory access flaws in the llama.cpp inference engine that can allow code execution. The rule matches the crafted tensor structures that overflow memory when the engine loads a model.