{
  "threat_severity" : "Low",
  "public_date" : "2026-06-22T21:55:42Z",
  "bugzilla" : {
    "description" : "vllm: vLLM: Information disclosure via integer truncation",
    "id" : "2491579",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2491579"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-824",
  "details" : [ "vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation of tensor dimensions in vLLM's GGUF dequantize kernels (csrc/quantization/gguf/gguf_kernel.cu) causes partial tensor processing. The output tensor is allocated at full size via torch::empty (uninitialized memory), but the dequantize CUDA kernel processes only a truncated number of elements. The unfilled portion of the output tensor retains whatever was previously in GPU memory. In multi-tenant inference deployments, this residual GPU memory may contain tensor data from other users' inference requests, constituting information disclosure. This vulnerability is fixed in 0.23.1rc0.", "A flaw was found in vLLM. Integer truncation of tensor dimensions in vLLM's GGUF dequantize kernels leads to partial tensor processing. This results in the output tensor retaining previously used GPU memory, which, in multi-tenant inference deployments, can expose sensitive tensor data from other users' requests. This constitutes an information disclosure vulnerability." ],
  "statement" : "Red Hat rates this issue as having Low impact for Red Hat AI products. The upstream issue is limited information disclosure via integer truncation in vLLM sampling parameters. Red Hat OpenShift AI, Red Hat AI Inference Server, and Red Hat Enterprise Linux AI images are not considered affected because untrusted clients cannot control the vulnerable parameters in supported deployment models.",
  "affected_release" : [ {
    "product_name" : "Red Hat AI Inference Server 3.3",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59138",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3.3::el9",
    "package" : "rhaiis/vllm-cuda-rhel9:1787161382"
  }, {
    "product_name" : "Red Hat AI Inference Server 3.3",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:59139",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3.3::el9",
    "package" : "rhaiis/vllm-rocm-rhel9:1787161803"
  }, {
    "product_name" : "Red Hat AI Inference Server 3.3",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60363",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3.3::el9",
    "package" : "rhaiis/vllm-spyre-rhel9:1787161776"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.3",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:62335",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
    "package" : "rhelai3/disk-image-cuda-rhel9:1788290314"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.3",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:62336",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
    "package" : "rhelai3/bootc-aws-cuda-rhel9:1788273908"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.3",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:62336",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
    "package" : "rhelai3/bootc-azure-cuda-rhel9:1788273909"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.3",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:62336",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
    "package" : "rhelai3/bootc-azure-rocm-rhel9:1788273908"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.3",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:62336",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
    "package" : "rhelai3/bootc-cuda-rhel9:1788260684"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.3",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:62336",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
    "package" : "rhelai3/bootc-gcp-cuda-rhel9:1788273977"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 3.3",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:62336",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3.3::el9",
    "package" : "rhelai3/bootc-rocm-rhel9:1788260620"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaiis/vllm-cpu-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaiis/vllm-neuron-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaiis/vllm-tpu-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaii/vllm-cpu-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaii/vllm-gaudi-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaii/vllm-neuron-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat AI Inference Server",
    "fix_state" : "Not affected",
    "package_name" : "rhaii/vllm-tpu-rhel9",
    "cpe" : "cpe:/a:redhat:ai_inference_server:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Not affected",
    "package_name" : "rhelai3/bootc-gaudi-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-kserve-agent-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-kserve-controller-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-kserve-router-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-kserve-storage-initializer-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-llm-d-kv-cache-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-vllm-gaudi-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-53923\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-53923\nhttps://github.com/vllm-project/vllm/commit/f219788f91952827132fa4fdf916427cd20d225e\nhttps://github.com/vllm-project/vllm/pull/44971\nhttps://github.com/vllm-project/vllm/security/advisories/GHSA-5jv2-g5wq-cmr4" ],
  "name" : "CVE-2026-53923",
  "mitigation" : {
    "value" : "No mitigation is required for unaffected deployments. Restrict untrusted access to inference APIs as a general hardening measure.",
    "lang" : "en:us"
  },
  "csaw" : false
}