Assertion Vulnerability in InternLM LMDeploy by InternLM
CVE-2026-92971
8.7HIGH
What is CVE-2026-92971?
InternLM's LMDeploy version 0.17.0 contains a reachable assertion vulnerability within the DistServe decode migration loop. This flaw allows unauthenticated attackers to submit a migration request with an empty list of remote block IDs, resulting in an AssertionError that can crash the inference engine. As a consequence, any subsequent inference requests are rendered inoperative, presenting a significant risk for service interruption and potential exploitation.
Affected Version(s)
lmdeploy 0 <= 0.17.0
