CyberRota Analysis
AI-GeneratedA denial of service vulnerability exists in vLLM versions up to 0.29.0, specifically affecting the P2P KV offloading feature when configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can exploit this flaw by providing arbitrary remote host and port values, leading to unreachable peer sessions that exhaust the context quota and crash the EngineCore, halting all inference processes. Organizations utilizing vLLM in their systems should prioritize addressing this vulnerability to maintain service availability and prevent potential disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference.
Related CVEs
Other vulnerabilities affecting the same vendor(s)