<Vulnerability name="CVE-2026-17512">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-07-27T12:30:10</PublicDate>
    <Bugzilla id="2507460" url="https://bugzilla.redhat.com/show_bug.cgi?id=2507460" xml:lang="en:us">
whisper.cpp: whisper.cpp: Information disclosure via out-of-bounds read
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>3.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-125</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in whisper.cpp. A local attacker can exploit an out-of-bounds read vulnerability in the `log_mel_spectrogram` function. This flaw could lead to the disclosure of sensitive information.
    </Details>
    <Statement xml:lang="en:us">
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the affected packages, refer to the linked references.
    </Statement>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-17512
https://nvd.nist.gov/vuln/detail/CVE-2026-17512
https://github.com/ggml-org/whisper.cpp/
https://github.com/ggml-org/whisper.cpp/issues/3923
https://github.com/ggml-org/whisper.cpp/pull/3925
https://vuldb.com/cve/CVE-2026-17512
https://vuldb.com/submit/798905
https://vuldb.com/vuln/383382
https://vuldb.com/vuln/383382/cti
    </References>
</Vulnerability>