SOURCE-LINKED INTELLIGENCE
GHSA-7m6h-x95x-82q5: vLLM: Cross-User Data Leak Vulnerability
### Summary An integer overflow in the act_and_mul_kernel kernel can cause the output of one user request to be incorporated into the response of another request within the same inference batch. Under certain conditions, the last request in a batch can receive a partial or complete copy of the first user's inference result, resulting in cross-user data leakage. ### Details The root cause is an integer overflow in the expression blockIdx.x * 2 * d at https://github.com/vllm-project/vllm/blob/ff712f6447093d07747c88680b9d006b119f5890/csrc/activation_kernels.cu#L82. As a result, the computation fo
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2026-09-08T20:24:49.000Z
- OSV AI package advisories · 2026-09-10T09:45:00.769Z
First collected: 2026-09-20T22:31:48.298Z. This is not the publication date.