Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | vLLM trust_remote_codeÈÆ¹ýÔ¶³Ì´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2026-27893 |
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2026-3-27 |
Îó²îÆÀ·Ö | 8.8 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
vLLMÊÇÒ»¸ö¸ßÐÔÄܵĴóÄ£×ÓÍÆÀí¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬×¨Îª´ó¹æÄ£ÓïÑÔÄ£×ӵĸßÍÌÍÂÁ¿¡¢µÍÑÓ³Ù°²ÅŶøÉè¼Æ¡£¡£¡£¡£Æä½¹µãÌØÕ÷°üÀ¨PagedAttention¸ßЧÄÚ´æÖÎÀí¡¢²¢Ðл¯µ÷ÀíÓÅ»¯ÒÔ¼°¶Ô¶àGPU¡¢ÂþÑÜʽÇéÐεÄÓÅÒìÖ§³Ö¡£¡£¡£¡£vLLM¼æÈÝHugging Face½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬±ãÓÚÄ£×Ó¿ìËÙ¼ÓÔØÓ뼯³É£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚÍÆÀíЧÀÍ¡¢AIÓ¦Óúó¶ËÓëÉú²ú¼¶Ä£×Ó°²Åų¡¾°¡£¡£¡£¡£
2026Äê3ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½vLLM trust_remote_codeÈÆ¹ýÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚvllm/model_executor/models/nemotron_vl.pyºÍvllm/model_executor/models/kimi_k25.pyÎļþÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´úÂëÖÐÓ²±àÂëÉèÖÃtrust_remote_code=True£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÓû§ÏÔʽÉèÖÃtrust-remote-code=False±»Èƹý¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâHuggingFaceÄ£×Ó¿ÍÕ»£¬£¬£¬£¬£¬£¬£¬ÔÚÄ£×Ó¼ÓÔØÀú³ÌÖÐÖ´ÐÐí§ÒâPython´úÂ룬£¬£¬£¬£¬£¬£¬»ñȡЧÀÍÆ÷Ö´ÐÐȨÏÞ£¬£¬£¬£¬£¬£¬£¬½ø¶øÊµÏÖϵͳ¿ØÖÆ¡¢Êý¾ÝÇÔÈ¡»òºáÏòÒÆ¶¯¡£¡£¡£¡£¸ÃÎó²îÆÆËðÁËtrust_remote_codeÇå¾²»úÖÆµÄÐÅÈνçÏߣ¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¼°Ð§Àͱ»ÍêÈ«½ÓÊÜ£¬£¬£¬£¬£¬£¬£¬±£´æ½Ï¸ßºÏ¹æÎ£º¦¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
vLLM >=0.10.1
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/vllm-project/vllm/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59/