CVE-2026-92971 PUBLISHED

InternLM LMDeploy through 0.17.0 Assertion Denial of Service

Assigner: VulnCheck
Reserved: 17.09.2026 Published: 17.09.2026 Updated: 17.09.2026

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor InternLM
Product lmdeploy
Versions Default: unaffected
  • affected from 0 to 0.17.0 (incl.)

Credits

  • Jiapeng Li finder
  • Jiajia Liu finder

References

Problem Types

  • Reachable Assertion CWE