CVE-2025-3162: InternLM LMDeploy PT File utils.py load_weight_ckpt deserialization
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function loadweightckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3162?
CVE-2025-3162 has been classified as critical due to its potential impact on security.
How do I fix CVE-2025-3162?
To fix CVE-2025-3162, you should upgrade InternLM LMDeploy to versions later than 0.7.1.
What component is affected by CVE-2025-3162?
The affected component in CVE-2025-3162 is the PT File Handler within the load_weight_ckpt function.
What type of vulnerability is CVE-2025-3162?
CVE-2025-3162 is a deserialization vulnerability that can lead to exploitation.
Can CVE-2025-3162 be exploited remotely?
CVE-2025-3162 primarily requires local access for exploitation, making it a critical concern.