Use of Uninitialized Resource Affecting tritonserver-backend-vllm-cuda-13.0 package, versions <25.11-r7


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.29% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-TRITONSERVERBACKENDVLLMCUDA130-17117983
  • published2 Jun 2026
  • disclosed27 Apr 2026

Introduced: 27 Apr 2026

CVE-2026-7141  (opens in a new tab)
CWE-908  (opens in a new tab)

How to fix?

Upgrade Chainguard tritonserver-backend-vllm-cuda-13.0 to version 25.11-r7 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream tritonserver-backend-vllm-cuda-13.0 package and not the tritonserver-backend-vllm-cuda-13.0 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in uninitialized resource. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. The patch is named 1ad67864c0c20f167929e64c875f5c28e1aad9fd. To fix this issue, it is recommended to deploy a patch.

CVSS Base Scores

version 3.1