CVE-2026-92971

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.

Published
September 17, 2026 2:18 PM
Last Modified
September 17, 2026 3:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-617

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.