CVE-2026-73558
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a request processed in the same inference batch to receive a partial or complete copy of another user's inference result. This issue is fixed in version 0.27.0.
Słabość
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a request processed in the same inference batch to receive a partial or complete copy of another user's inference result. This issue is fixed in version 0.27.0.
Źródła
- https://github.com/vllm-project/vllm/commit/451227cb3ff07989698fed982c2d3e4300257924
- https://github.com/vllm-project/vllm/issues/42860
- https://github.com/vllm-project/vllm/pull/49660
- https://github.com/vllm-project/vllm/releases/tag/v0.27.0
- https://github.com/vllm-project/vllm/security/advisories/GHSA-7m6h-x95x-82q5
- https://github.com/vllm-project/vllm/security/advisories/GHSA-7m6h-x95x-82q5
Znajdź błąd, zanim zrobi to atakujący.
Zaloguj się przez GitHub i uruchom pierwszy audyt w niecałą minutę. Plan darmowy nie wymaga karty kredytowej.