PT-2026-95640 · Vllm · Vllm

·

CVE-2026-93841

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vLLM versions prior to 0.30.0
Description A memory corruption issue exists in the Triton bincount kernel function. The problem occurs when prompt token IDs index the penalty prompt-presence bitset without performing bounds checking against the vocabulary size. An attacker can exploit this by submitting multimodal audio requests containing tokens equal to the vocabulary size, leading to out-of-bounds writes. This action corrupts the sampler state of concurrent requests and alters the repetition penalty behavior.
Recommendations Update to version 0.30.0.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93841
OPENSUSE-SU-2026:11867-1
PYSEC-2026-3999

Affected Products

Vllm