PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105192 LMCache CVE debrief

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.

Vendor
LMCache
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for LMCache instances, especially those running in multiprocess mode or as root, should assess exposure and prioritize patching or mitigations. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify exposure and apply patches or mitigations as available.

Why it matters

Defenders should prioritize verifying exposure of LMCache instances running in multiprocess mode, especially those running as root, and apply patches or mitigations as available due to the critical severity and potential for unauthenticated code execution.

  • Unauthenticated code execution as the user the LMCache process runs as
  • Potential for privilege escalation if the process runs as root
  • Possible disruption of service due to unauthorized code execution

Technical summary

LMCache multiprocess mode opens an unauthenticated ZeroMQ ROUTER, allowing worker processes to register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as.

Defensive priority

Defenders should prioritize verifying exposure of LMCache instances running in multiprocess mode, especially those running as root, and apply patches or mitigations as available.

Recommended defensive actions

  • Verify LMCache instances running in multiprocess mode and apply patches or mitigations as available
  • Restrict access to the transport port (default 5555) to trusted sources
  • Monitor for suspicious activity on the transport port
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected product, attack vector, and technical description. The vulnerability affects LMCache instances running in multiprocess mode, especially those running as root. Defenders should verify exposure and prioritize patching or mitigations. The official CVE Program record and NIST NVD detail page provide additional information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105192 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105192

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105192 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105192

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105192.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/LMCache/LMCache

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://pypi.org/project/lmcache/

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/platform/base/ipc_wrapper.py

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/LMCache/LMCache/blob/v0.3.9/lmcache/v1/multiprocess/custom_types.py

    Supplemental source - technical-description

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.