Impact
The vulnerability is an improper input validation flaw (CWE‑20) in the vLLM Hardware Plugin for Intel Gaudi software, allowing a local authenticated user to cause a denial of service when the plugin runs in user mode (Ring 3). The flaw can terminate the plugin process or consume excessive resources, leading to lost availability of the application that relies on the plugin. No confidentiality or integrity impact is recorded.
Affected Systems
The affected product is Intel’s vLLM Hardware Plugin for Intel Gaudi software, versions prior to 0.16.0. The issue exists when the plugin operates in Ring 3 and can be triggered by user applications that use the plugin. Devices running these software versions on Intel Gaudi hardware are impacted.
Risk and Exploitability
The CVSS base score of 6.8 indicates a medium severity risk. The EPSS score is below 1 %, implying a very low likelihood of exploitation at the moment, and the vulnerability is not in the CISA KEV catalog. The attack requires local access with an authenticated user and low complexity, meaning an insider or compromised account could exploit the flaw. The high availability impact means that if an attacker succeeds, the affected system will experience a denial of service.
OpenCVE Enrichment