Description
InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requests to the proxy endpoint that accumulate unreleased scheduler metadata and memory until the prefill worker is out-of-memory killed.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when InternLM LMDeploy's DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user‑facing session IDs instead of internal scheduler keys. As a result, each unauthenticated completion request to the proxy endpoint accumulates unreleased scheduler metadata and memory. The attacker can amplify the effect by sending many requests, eventually exhausting the prefill worker's memory and causing it to be killed by the operating system. This leads to a denial of service. The weakness is an unchecked resource that is not released, which corresponds to CWE‑772.

Affected Systems

InternLM:lmdeploy through version 0.17.0 is affected. The library can be accessed from the InternLM GitHub repository. No further vendor or product versions are listed as impacted in the CNA data.

Risk and Exploitability

The CVSS score of 8.7 places the vulnerability in the high severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not yet be publicly exploited. The likely attack vector is network: an unauthenticated attacker can send repeated completion requests to the exposed proxy endpoint. Because the exploitation does not require privileged access and solely depends on the prefill worker's memory limits, the risk is significant for any environment that runs the vulnerable LMDeploy component with the disaggregation feature enabled.

Generated by OpenCVE AI on September 17, 2026 at 21:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched or newer version of lmdeploy that correctly releases scheduler sessions for prefill/decode disaggregation mode.
  • Apply network‑layer rate limiting or firewall rules to restrict or throttle completion requests to the LMDeploy proxy endpoint, mitigating memory exhaustion attempts.
  • Monitor memory usage of the prefill worker and configure alerts for high consumption; consider disabling disaggregation mode or adjusting worker resource limits.

Generated by OpenCVE AI on September 17, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requests to the proxy endpoint that accumulate unreleased scheduler metadata and memory until the prefill worker is out-of-memory killed.
Title InternLM LMDeploy through 0.17.0 Memory Exhaustion via Session ID Mismatch
First Time appeared Internlm
Internlm lmdeploy
Weaknesses CWE-772
CPEs cpe:2.3:a:internlm:lmdeploy:*:*:*:*:*:*:*:*
Vendors & Products Internlm
Internlm lmdeploy
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Internlm Lmdeploy
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T19:18:29.048Z

Reserved: 2026-09-17T13:55:53.252Z

Link: CVE-2026-92983

cve-icon Vulnrichment

Updated: 2026-09-18T19:18:08.931Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:17:01.540

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime