CVE-2026-100649

⚪ Do wiadomości

Obejście limitów zasobów w vLLM pozwala atakującym na wyczerpanie pamięci GPU.

CVSS
3.7
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits and exhaust unaccounted GPU memory.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-09-26 14:16:47 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:16:58 UTC
Referencje