Description
Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. Authorized adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper input validation flaw (CWE‑20) in the vLLM Hardware Plugin for Intel Gaudi software, allowing a local authenticated user to cause a denial of service when the plugin runs in user mode (Ring 3). The flaw can terminate the plugin process or consume excessive resources, leading to lost availability of the application that relies on the plugin. No confidentiality or integrity impact is recorded.

Affected Systems

The affected product is Intel’s vLLM Hardware Plugin for Intel Gaudi software, versions prior to 0.16.0. The issue exists when the plugin operates in Ring 3 and can be triggered by user applications that use the plugin. Devices running these software versions on Intel Gaudi hardware are impacted.

Risk and Exploitability

The CVSS base score of 6.8 indicates a medium severity risk. The EPSS score is below 1 %, implying a very low likelihood of exploitation at the moment, and the vulnerability is not in the CISA KEV catalog. The attack requires local access with an authenticated user and low complexity, meaning an insider or compromised account could exploit the flaw. The high availability impact means that if an attacker succeeds, the affected system will experience a denial of service.

Generated by OpenCVE AI on August 12, 2026 at 21:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the vLLM Hardware Plugin to version 0.16.0 or later, which includes input validation fixes.
  • Restrict user privileges that can load or execute the plugin, ensuring only trusted accounts have the necessary rights.
  • Implement process monitoring or resource limits to contain resource exhaustion that could lead to denial of service.

Generated by OpenCVE AI on August 12, 2026 at 21:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel vllm Hardware Plugin For Intel(r) Gaudi(r) Software
Vendors & Products Intel
Intel vllm Hardware Plugin For Intel(r) Gaudi(r) Software

Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Denial of Service in vLLM Hardware Plugin for Intel Gaudi

Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. Authorized adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Intel Vllm Hardware Plugin For Intel(r) Gaudi(r) Software
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:23:08.238Z

Reserved: 2026-03-20T03:00:17.141Z

Link: CVE-2026-27765

cve-icon Vulnrichment

Updated: 2026-08-12T15:23:02.316Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:56.720

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-27765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:40:19Z

Weaknesses
  • CWE-20

    Improper Input Validation