Impact
The vulnerability arises when InternLM LMDeploy's DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user‑facing session IDs instead of internal scheduler keys. As a result, each unauthenticated completion request to the proxy endpoint accumulates unreleased scheduler metadata and memory. The attacker can amplify the effect by sending many requests, eventually exhausting the prefill worker's memory and causing it to be killed by the operating system. This leads to a denial of service. The weakness is an unchecked resource that is not released, which corresponds to CWE‑772.
Affected Systems
InternLM:lmdeploy through version 0.17.0 is affected. The library can be accessed from the InternLM GitHub repository. No further vendor or product versions are listed as impacted in the CNA data.
Risk and Exploitability
The CVSS score of 8.7 places the vulnerability in the high severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not yet be publicly exploited. The likely attack vector is network: an unauthenticated attacker can send repeated completion requests to the exposed proxy endpoint. Because the exploitation does not require privileged access and solely depends on the prefill worker's memory limits, the risk is significant for any environment that runs the vulnerable LMDeploy component with the disaggregation feature enabled.
OpenCVE Enrichment