Could you attach with a debugger (or share a WinDbg/crash dump) next time it happens, and confirm the exact llama-server binary/CUDA backend version being invoked? I'll try to reproduce on a ...