Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8768

Опубликовано: 22 авг. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

Отчет

This vulnerability can only be exploited when vLLM is serving GPT-2 models, other models are not affected by this issue. As this flaw allows remote users to cause a denial of service, it has been rated with an important severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-nvidia-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/instructlab-nvidia-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2311895vllm: A completions API request with an empty prompt will crash the vllm API server.

EPSS

Процентиль: 27%
0.00095
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

CVSS3: 7.5
debian
больше 1 года назад

A flaw was found in the vLLM library. A completions API request with a ...

CVSS3: 7.5
github
больше 1 года назад

vLLM denial of service vulnerability

EPSS

Процентиль: 27%
0.00095
Низкий

7.5 High

CVSS3