CVE-2026-92971: InternLM LMDeploy through 0.17.0 Assertion Denial of Service

Published Sep 17, 2026
·
Updated

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migrationrequest with an empty remoteblockids list to trigger an AssertionError that crashes the engine loop and causes subsequent inference requests to fail.

Affected Software

1 affected component
InternLM LMDeploy<=0.17.0

Event History

Sep 17, 2026
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this denial of service?

LMDeploy versions through 0.17.0 are affected where the DistServe decode migration path is reachable. The issue can terminate the inference engine, causing subsequent inference requests to fail.

2

Does exploitation require authentication or user interaction?

No. The vulnerability is reachable by unauthenticated attackers and requires no user interaction or elevated privileges.

3

What request triggers the crash?

An attacker can submit a migration_request with an empty remote_block_ids list. This triggers an AssertionError in the decode migration loop and crashes the engine loop.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203