vLLM是vLLM团队开源的一个适用于 LLM 的高吞吐量和内存高效推理和服务引擎。 vLLM 0.27.0之前版本存在资源管理错误漏洞,该漏洞源于未能正确将DeepStream分类为GPU后端并省略解码路径中的像素限制,可能导致未经身份验证的攻击者在请求时激活DeepStream以初始化进程级GPU解码池并提交绕过资源控制的视频,造成并发请求的部分拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vllm-project | vllm | < 0.27.0 |
affected |
0.27.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vllm-project | vllm | 0 ~ 0.27.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet