CyberRota Analysis
AI-GeneratedLightLLM versions up to 1.2.0 are vulnerable to a memory exhaustion issue in the NCCL control channel, which can be exploited by unauthenticated attackers to overload KV-transfer worker memory. By invoking the exposed_set_value method, attackers can store unlimited key-value pairs, leading to worker process crashes and potential node failures. Organizations utilizing LightLLM should prioritize patching this vulnerability to mitigate the risk of service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.