PT-2026-96317 · Vllm · Vllm
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.29.1
Description
The Mooncake connector fails to properly manage GPU KV cache block ownership during prefill/decode disaggregated deployments when concurrent child requests share a single transfer ID. An attacker can cause GPU memory exhaustion by submitting completion requests containing multiple prompts. This action leads to the accumulation of orphaned KV cache blocks—memory blocks that are no longer associated with an active request but are not released—which persist until the process is restarted, eventually blocking legitimate requests from executing.
Recommendations
Update vLLM to a version newer than 0.29.0.
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm