Skip to content

Withdraw/update GHSA-x368-4g9h-fvv4 (CVE-2026-7141) - #9158

Open
ppham-nv wants to merge 1 commit into
github:ppham-nv/advisory-improvement-9158from
ppham-nv:ppham-GHSA-x368-4g9h-fvv4
Open

Withdraw/update GHSA-x368-4g9h-fvv4 (CVE-2026-7141)#9158
ppham-nv wants to merge 1 commit into
github:ppham-nv/advisory-improvement-9158from
ppham-nv:ppham-GHSA-x368-4g9h-fvv4

Conversation

@ppham-nv

@ppham-nv ppham-nv commented Aug 18, 2026

Copy link
Copy Markdown

I think this advisory should be withdrawn as written.

The "patched" commit 1ad67864 is the first of two commits on vllm-project/vllm#39283, which is still open, and it was superseded by 01b9f9ee after review. It's on no branch or tag. It will resolve if you hit vllm-project/vllm@1ad6786, because GitHub keeps PR commits even if it's in a fork but nothing ships it officially.

The named patch might not change the reported behavior see vllm-project/vllm#39146 (comment): applying that exact patch, with instrumentation confirming the zeroing ran, left the reported divergence in place, while VLLM_BATCH_INVARIANT=1 removed it entirely. (To be confirmed )

I propose to update or withdrawn because the advisory points at a commit that was never released and a fix that doesn't resolve what was reported. Whatever is behind the original report may be something else entirely — if a real issue is confirmed there, it would need its own analysis and an update to this advisory/ or a new advisory.

The advisory names 1ad67864 as the patch, but that commit is on no branch
or tag in vllm-project/vllm and ships in no release. Testing in the linked
issue also shows the named patch does not change the reported behavior.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions
github-actions Bot changed the base branch from main to ppham-nv/advisory-improvement-9158 August 18, 2026 18:39
@ppham-nv ppham-nv changed the title Withdraw GHSA-x368-4g9h-fvv4 (CVE-2026-7141) Withdraw/update GHSA-x368-4g9h-fvv4 (CVE-2026-7141) Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant