vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Published Sep 16, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.55%
Description
vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards that choice to VideoMediaIO even when startup configuration selected a software decoder. The engine's _reserve_mm_ipc_gpu_memory logic budgets decoder memory only from static configuration, so the request-selected VIDEO_LOADER_REGISTRY backend can create a CUDA context, decoder surfaces, and decoded-frame allocations that were not removed from the engine's KV-cache budget. An attacker able to submit video requests to a video-capable GPU deployment with PyNvVideoCodec installed can exhaust shared GPU memory, causing request failures, worker crashes, or denial of service. The first release containing the fix is version 0.28.0.
Affected products
-
- Version < 0.28.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vllm-Project | Vllm | n/a |
|
No data.
No data.
Red Hat AI Inference Server
rhaii/vllm-cpu-rhel9
Fix deferred
Red Hat AI Inference Server
rhaii/vllm-cuda-rhel9
Fix deferred
Red Hat AI Inference Server
rhaii/vllm-gaudi-rhel9
Fix deferred
Red Hat AI Inference Server
rhaii/vllm-neuron-rhel9
Fix deferred
Red Hat AI Inference Server
rhaii/vllm-rocm-rhel9
Fix deferred
Red Hat AI Inference Server
rhaii/vllm-spyre-rhel9
Fix deferred
Red Hat AI Inference Server
rhaii/vllm-tpu-rhel9
Fix deferred
Red Hat AI Inference Server
rhaiis/vllm-cpu-rhel9
Fix deferred
Red Hat AI Inference Server
rhaiis/vllm-cuda-rhel9
Fix deferred
Red Hat AI Inference Server
rhaiis/vllm-neuron-rhel9
Fix deferred
Red Hat AI Inference Server
rhaiis/vllm-rocm-rhel9
Fix deferred
Red Hat AI Inference Server
rhaiis/vllm-spyre-rhel9
Fix deferred
Red Hat AI Inference Server
rhaiis/vllm-tpu-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-aws-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-rocm-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gcp-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-agent-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-controller-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-router-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-storage-initializer-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-llm-d-kv-cache-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th-torch-cuda-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-gaudi-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AI Inference Server | rhaii/vllm-cpu-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaii/vllm-cuda-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaii/vllm-gaudi-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaii/vllm-neuron-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaii/vllm-rocm-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaii/vllm-spyre-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaii/vllm-tpu-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-cpu-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-cuda-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-neuron-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-rocm-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-spyre-rhel9 | Fix deferred | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-tpu-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-aws-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-rocm-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gcp-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-agent-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-controller-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-router-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-storage-initializer-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-llm-d-kv-cache-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th-torch-cuda-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-gaudi-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-69147 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2535581 Issue Tracking
- https://github.com/advisories/GHSA-8pw2-6jv3-mj5j Advisory
- https://github.com/vllm-project/vllm/commit/283893c72292ede38d277e3cd2b9b64c3e4f1dda x_refsource_MISC
- https://github.com/vllm-project/vllm/commit/ba22152096b2484faa3579624a253d54804d876d x_refsource_MISC
- https://github.com/vllm-project/vllm/pull/47259 x_refsource_MISC
- https://github.com/vllm-project/vllm/releases/tag/v0.25.0
- https://github.com/vllm-project/vllm/security/advisories/GHSA-8pw2-6jv3-mj5j exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-69147
- https://www.cve.org/CVERecord?id=CVE-2026-69147
Change history (0)
No recorded changes yet.