Executive brief
A vulnerability exists in whisper.cpp, a high-performance library used for speech-to-text transcription. An attacker with local access to the system could provide a specially crafted model file that causes the application to crash unexpectedly. This results in a denial-of-service, potentially disrupting automated transcription services or applications relying on this library.
Technical details
A reachable assertion vulnerability exists in the ggml_ftype_to_ggml_type function within ggml/src/ggml.c of whisper.cpp (commit 95ea8f9b). The issue occurs when whisper_model_load() passes a model-declared 'ftype' to the conversion function; if the ftype is invalid (e.g., 5, 6, or ≥27 after modulo 1000), the code sets an error sentinel that triggers a GGML_ASSERT. Because GGML_ASSERT is not compiled out in release builds, this leads to an immediate process abort (ggml_abort). An attacker can exploit this by providing a malformed 48-byte PoC model file to trigger a crash. As of the advisory date, the project has been informed but a formal patch has not been confirmed.
Affected products
- ggml-org whisper.cpp 95ea8f9b
Timeline
- 2026-07-03: disclosed: Issue reported to the project maintainers via GitHub issue #3924
- 2026-07-27: advisory: CVE-2026-17513 published by VulDB/NVD