Bug 2538247 (CVE-2026-94622)
| Summary: | CVE-2026-94622 vllm: vLLM: Denial of Service via Incomplete NIXL KV Transfer Metadata | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | alinfoot, bbrownin, dtrifiro, weaton |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in vLLM. A remote attacker can exploit this vulnerability by sending requests with incomplete `kv_transfer_params` dictionary entries to the NIXL connector's metadata handling. This can trigger an uncaught error in the EngineCore scheduling, leading to the termination of the decode engine. Consequently, all routed requests will fail until a manual restart, resulting in a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-22 17:29:32 UTC
|