Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 22, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 22, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 22, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 22, 2025

      Sam Altman says ChatGPT’s viral Ghibli effect “forced OpenAI to do a lot of unnatural things”

      May 22, 2025

      How to get started with Microsoft Copilot on Windows 11

      May 22, 2025

      Microsoft blocks employees from sending emails that mention “Palestine” or “Gaza”

      May 22, 2025

      I missed out on the Clair Obscur: Expedition 33 Collector’s Edition but thankfully, the developers are launching something special

      May 22, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Perficient is Shaping the Future of Salesforce Innovation

      May 22, 2025
      Recent

      Perficient is Shaping the Future of Salesforce Innovation

      May 22, 2025

      Opal – Optimizely’s AI-Powered Marketing Assistant

      May 22, 2025

      Content Compliance Without the Chaos: How Optimizely CMP Empowers Financial Services Marketers

      May 22, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Sam Altman says ChatGPT’s viral Ghibli effect “forced OpenAI to do a lot of unnatural things”

      May 22, 2025
      Recent

      Sam Altman says ChatGPT’s viral Ghibli effect “forced OpenAI to do a lot of unnatural things”

      May 22, 2025

      How to get started with Microsoft Copilot on Windows 11

      May 22, 2025

      Microsoft blocks employees from sending emails that mention “Palestine” or “Gaza”

      May 22, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-47277 – NVIDIA vLLM Unauthenticated Remote Code Execution

    CVE-2025-47277 – NVIDIA vLLM Unauthenticated Remote Code Execution

    May 20, 2025

    CVE ID : CVE-2025-47277

    Published : May 20, 2025, 6:15 p.m. | 1 hour, 44 minutes ago

    Description : vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the `PyNcclPipe` KV cache transfer integration with the V0 engine. No other configurations are affected. vLLM supports the use of the `PyNcclPipe` class to establish a peer-to-peer communication domain for data transmission between distributed nodes. The GPU-side KV-Cache transmission is implemented through the `PyNcclCommunicator` class, while CPU-side control message passing is handled via the `send_obj` and `recv_obj` methods on the CPU side.​ The intention was that this interface should only be exposed to a private network using the IP address specified by the `–kv-ip` CLI parameter. The vLLM documentation covers how this must be limited to a secured network. The default and intentional behavior from PyTorch is that the `TCPStore` interface listens on ALL interfaces, regardless of what IP address is provided. The IP address given was only used as a client-side address to use. vLLM was fixed to use a workaround to force the `TCPStore` instance to bind its socket to a specified private interface. As of version 0.8.5, vLLM limits the `TCPStore` socket to the private interface as configured.

    Severity: 9.8 | CRITICAL

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Hostinger
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-46724 – Langroid TableChatAgent Code Injection Vulnerability
    Next Article CVE-2025-37985 – Linux Kernel USB Wdm Wwan Buffer Overflow

    Related Posts

    Development

    Smashing Security podcast #418: Grid failures, Instagram scams, and Legal Aid leaks

    May 22, 2025
    Development

    FBI Seizes Key Domains Behind LummaC2 Malware Used in Global Credential Theft

    May 22, 2025
    Leave A Reply Cancel Reply

    Hostinger

    Continue Reading

    From Wordle to Robotics: Q-SFT Unleashes LLMs’ Potential in Sequential Decision-Making

    Development

    HP’s sleek AI PC hits an absurdly low price — the cheapest entry to all-day battery life

    News & Updates

    Elon Musk comes clean about Path of Exile 2 and Diablo 4 credentials and I am shocked — SHOCKED I tell you

    News & Updates

    Chrome on Android is making it easier to access bookmarks and history

    Development
    Hostinger

    Highlights

    Development

    Achieve security compliance with Wazuh File Integrity Monitoring

    May 22, 2024

    File Integrity Monitoring (FIM) is an IT security control that monitors and detects file changes…

    RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control

    April 30, 2025

    CVE-2025-24132 – Apple AirPlay Local Network Denial of Service

    April 30, 2025

    LockBit Ransomware Group Allegedly Strikes Heras UK in Cyberattack

    May 30, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.