<Vulnerability name="CVE-2026-17513">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-07-27T12:45:10</PublicDate>
    <Bugzilla id="2507471" url="https://bugzilla.redhat.com/show_bug.cgi?id=2507471" xml:lang="en:us">
whisper.cpp: whisper.cpp: Denial of Service via ftype argument manipulation
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>3.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-617</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in whisper.cpp, a library for machine learning. A local attacker can exploit a vulnerability in the ggml_ftype_to_ggml_type function by manipulating the ftype argument. This manipulation leads to a reachable assertion, which can cause the application to terminate, resulting in a Denial of Service (DoS).
    </Details>
    <Statement xml:lang="en:us">
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the affected packages, refer to the linked references.
    </Statement>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-17513
https://nvd.nist.gov/vuln/detail/CVE-2026-17513
https://github.com/ggml-org/whisper.cpp/
https://github.com/ggml-org/whisper.cpp/issues/3924
https://vuldb.com/cve/CVE-2026-17513
https://vuldb.com/submit/799055
https://vuldb.com/vuln/383383
https://vuldb.com/vuln/383383/cti
    </References>
</Vulnerability>