REDHAT-BUG-2452055: High severity vllm vulnerability
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode trustremotecode=True when loading sub-components, bypassing the user's explicit --trust-remote-code=False security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vLLMto a version that resolves this vulnerability.Fixed in 0.18.0
Event History
Frequently Asked Questions
What is the risk level of REDHAT-BUG-2452055?
The risk level of REDHAT-BUG-2452055 is categorized as high.
What is the severity score of REDHAT-BUG-2452055?
The severity score of REDHAT-BUG-2452055 is rated at 7.
What versions of vLLM are affected by REDHAT-BUG-2452055?
vLLM versions from 0.10.1 to prior to 0.18.0 are affected by REDHAT-BUG-2452055.
How does REDHAT-BUG-2452055 impact security?
REDHAT-BUG-2452055 allows the hardcoding of trust_remote_code=True, bypassing user security opt-out settings.
What should be done to mitigate REDHAT-BUG-2452055?
To mitigate REDHAT-BUG-2452055, upgrade vLLM to version 0.18.0 or later.