vLLM through 0.29.0 contains a memory corruption...
Moderate severity
Unreviewed
Published
Sep 18, 2026
to the GitHub Advisory Database
•
Updated Sep 18, 2026
Description
Published by the National Vulnerability Database
Sep 18, 2026
Published to the GitHub Advisory Database
Sep 18, 2026
Last updated
Sep 18, 2026
vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes that corrupt concurrent requests' sampler state and alter repetition penalty behavior.
References