Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-105192: lmcache may run attacker code through unauthenticated local port

CVE-2026-105192 · published 3 days ago
Summary

The lmcache service, when used in its distributed mode, opens a network socket that anyone on the network can reach. An attacker can send a specially crafted message to that socket and cause the service to execute arbitrary commands, potentially with root privileges. Protect the system by configuring the service to listen only on localhost, running it under a non‑administrative account, and applying firewall rules or network segmentation to block external access.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
lmcache lmcache <= *
Original advisory text
LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization
LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-306Missing Authentication for Critical Function
CWE-502Deserialization of Untrusted Data
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-105192 · MITRE
Track software like this
Free during beta