PT-2026-99320 · Vllm · Vllm
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vLLM versions prior to 0.29.0
Description
A resource-limit bypass exists in the PyNvVideoCodec decoder allocation. This issue occurs because sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits, leading to the exhaustion of unaccounted GPU memory.
Recommendations
Update vLLM to version 0.29.0 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vllm