{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lmdeploy--0.17.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:internlm:lmdeploy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92983"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LMDeploy (\u003c= 0.17.0)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["InternLM"],"content_html":"\u003cp\u003eInternLM LMDeploy through version 0.17.0 contains a vulnerability within the DistServe prefill/decode disaggregation mode. The flaw originates from the proxy component's improper handling of scheduler sessions. Specifically, the proxy incorrectly utilizes user-facing session IDs instead of internal scheduler keys, preventing the system from properly releasing scheduler sessions upon request completion.\u003c/p\u003e\n\u003cp\u003eUnauthenticated attackers can exploit this behavior by flooding the proxy endpoint with specifically crafted completion requests. Because the system fails to clean up these sessions, they accumulate indefinitely, leading to a rapid consumption of scheduler metadata and system memory. This resource exhaustion eventually forces the prefill worker process into an out-of-memory (OOM) killed state, effectively causing a persistent denial of service. The vulnerability is critical for environments where LMDeploy is exposed to public or untrusted network segments, as it requires no authentication to initiate the exploit.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unavailability of the affected LLM inference service. In a production environment using DistServe, the termination of the prefill worker halts the processing of all incoming inference requests. Organizations relying on LMDeploy for automated AI workloads will face service disruption, requiring a manual restart of the worker nodes and potential remediation of the underlying memory leak by upgrading or patching the LMDeploy configuration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of internet-facing LMDeploy instances and verify their version. Upgrade to a version of LMDeploy that resolves the session management flaw in DistServe mode. If an immediate upgrade is not feasible, restrict access to the LMDeploy proxy endpoint using network-layer controls, such as IP allowlisting or authentication proxies, to prevent unauthenticated access by external entities. Monitor resource utilization metrics on worker nodes for unexpected spikes in memory usage linked to the proxy service.\u003c/p\u003e\n","date_modified":"2026-09-17T16:00:04Z","date_published":"2026-09-17T16:00:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lmdeploy-dos/","summary":"InternLM LMDeploy version 0.17.0 and earlier is vulnerable to a denial-of-service attack due to improper session management in DistServe mode, allowing unauthenticated attackers to cause an out-of-memory failure on the prefill worker.","title":"Denial of Service Vulnerability in InternLM LMDeploy","url":"https://feed.craftedsignal.io/briefs/2026-09-lmdeploy-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - LMDeploy (\u003c= 0.17.0)","version":"https://jsonfeed.org/version/1.1"}