The vendor explicitly identifies these products as affected by this CVE.
- rhaii/vllm-cpu-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-gaudi-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-neuron-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-rocm-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-spyre-rhel9 as a component of Red Hat AI Inference Server
- rhaii/vllm-tpu-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-cpu-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-cuda-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-neuron-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-rocm-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-spyre-rhel9 as a component of Red Hat AI Inference Server
- Summary
- A flaw was found in vLLM. Unauthenticated attackers can exploit this vulnerability by activating the DeepStream backend during a request. This allows them to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, leading to a partial denial of service for concurrent requests.
- Remediation
- Fix deferred
