PT-2026-102937 · Lightllm · Lightllm
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
LightLLM versions prior to 1.2.1
Description
A memory exhaustion issue exists in the NCCL control channel when the software is started with the
--pd trans mode nccl configuration. Unauthenticated attackers can exploit this by calling the exposed set value() method to store an unlimited number of key-value pairs without size restrictions. This action exhausts the memory of the KV-transfer worker, leading to a process crash and subsequent node failure.Recommendations
Update LightLLM to version 1.2.1 or later.
As a temporary mitigation, avoid starting the software with the
--pd trans mode nccl flag.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightllm