CVE-2026-92971

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_ids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 HIGH SEVERITY: CVE-2026-92971 (CVSS 7.5) InternLM LMDeploy ≤0.17.0 — Reachable assertion flaw allows unauthenticated attackers to crash inference engine via empty migration_request. Impact: DoS, service disruption Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/75djQ9cVDA

    0000018
    140 followersView on X

Explore more