HIGH7.5
GHSA-89qx-m49c-8crf
Ollama Allows Out-of-Bounds Read
Details
A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause of the issue is an out-of-bounds read in the gguf.go file.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/ollama/ollama
Introduced in:
0No fixed version published yet for github.com/ollama/ollama (go modules). Pin to a known-safe version or switch to an alternative.