REDHAT-BUG-2487813: High severity vllm vllm vulnerability
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the VideoMediaIO.loadbase64() method. When processing video/jpeg data URLs, the method splits the base64 data string on commas to extract individual JPEG frames without enforcing a frame count limit. An attacker can exploit this by crafting a single API request containing thousands of comma-separated base64-encoded JPEG frames in a data URL, causing the server to decode all frames into memory and crash due to excessive memory consumption. This vulnerability is reachable via the OpenAI-compatible chat completions API and does not require authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2487813?
The severity of REDHAT-BUG-2487813 is high, rated at 7.
What types of attacks can be executed due to REDHAT-BUG-2487813?
REDHAT-BUG-2487813 allows for an Out-of-Memory (OOM) Denial of Service (DoS) attack.
Which versions are affected by REDHAT-BUG-2487813?
vLLM versions 0.8.0 and later are affected by REDHAT-BUG-2487813.
How do I fix REDHAT-BUG-2487813?
To fix REDHAT-BUG-2487813, update to a patched version of vLLM that addresses the unbounded frame count processing issue.
What method is responsible for the vulnerability in REDHAT-BUG-2487813?
The vulnerability in REDHAT-BUG-2487813 originates from the `VideoMediaIO.load_base64()` method.