"The loader is the trust boundary" belongs on the first page of every model-hosting guide. People apply real scrutiny to pickle files because that lesson was learned loudly, then download a .gguf with the mental model of a JPEG, while the parser turning it into heap allocations and tensor shapes is C++ reading attacker-controlled counts.
A zero dimension killing llama.cpp on a division is close to the friendly version of this bug. The same class quietly hands you an allocation size someone else chose.
The practical takeaway for anyone running a model server: neither the hub nor the file extension is a trust boundary, so validate shapes before the loader gets to, and treat model fetching with the same care as any other untrusted download.