VDB
Sign up
HIGH7.5

GHSA-89qx-m49c-8crf

Ollama Allows Out-of-Bounds Read

Details

A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause of the issue is an out-of-bounds read in the gguf.go file.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ollama/ollama
Introduced in: 0

No fixed version published yet for github.com/ollama/ollama (go modules). Pin to a known-safe version or switch to an alternative.

References