Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail. | |
| Title | InternLM LMDeploy through 0.17.0 Assertion Denial of Service | |
| First Time appeared |
Internlm
Internlm lmdeploy |
|
| Weaknesses | CWE-617 | |
| CPEs | cpe:2.3:a:internlm:lmdeploy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Internlm
Internlm lmdeploy |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T14:29:19.612Z
Reserved: 2026-09-17T13:23:54.594Z
Link: CVE-2026-92971
Updated: 2026-09-17T14:29:09.606Z
Status : Received
Published: 2026-09-17T14:18:03.190
Modified: 2026-09-17T15:17:01.330
Link: CVE-2026-92971
No data.
OpenCVE Enrichment
No data.
