Description
vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty behavior.
Published: 2026-09-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sampler State Corruption
Action: Immediate Patch
AI Analysis

Impact

vLLM versions up to 0.29.0 contain a memory corruption flaw in the Triton _bincount_kernel where prompt token IDs are used without bounds checking against the vocabulary size. An attacker can craft multimodal audio requests containing tokens equal to the vocabulary size, causing out‑of‑bounds writes to the penalty prompt‑presence bitset. This corrupts the sampler state used by concurrent requests, altering repetition‑penalty behavior and producing incorrect or unpredictable responses. The vulnerability does not provide direct code execution but can affect the integrity of generated output.

Affected Systems

The affected software is the open‑source vLLM library from the vllm‑project, with versions 0.29.0 and earlier. Any deployment that enables multimodal audio requests and relies on the Triton sampling kernel is susceptible.

Risk and Exploitability

The CVSS score of 6.3 classifies the issue as moderate severity. The EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via network access to an exposed vLLM API that accepts multimodal audio requests; an attacker can craft requests containing token IDs equal to the vocabulary size. Based on the description, it is inferred that the attacker must be able to submit such crafted requests to trigger the out‑of‑bounds write. Exploitation does not provide arbitrary code execution but can corrupt sampler state and alter repetition‑penalty behavior for concurrent requests.

Generated by OpenCVE AI on September 23, 2026 at 02:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a vLLM release that includes the Triton kernel bounds‑check patch (e.g., v0.30.0 or later).
  • If an upgrade is not yet feasible, restrict the vLLM API to trusted hosts or networks to limit exposure.
  • Disable or remove multimodal audio request handling until the patch is applied, if the application allows such configuration.

Generated by OpenCVE AI on September 23, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Low


Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty behavior.
Title vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs
First Time appeared Vllm
Vllm vllm
Weaknesses CWE-129
CPEs cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
Vendors & Products Vllm
Vllm vllm
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:15.994Z

Reserved: 2026-09-18T18:16:52.304Z

Link: CVE-2026-93841

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:55.356Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:34.357

Modified: 2026-09-28T18:35:40.697

Link: CVE-2026-93841

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-18T19:06:06Z

Links: CVE-2026-93841 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T02:15:17Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-787

    Out-of-bounds Write