CVE-2025-0317

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Service (DoS) attack.
References
Link Resource
https://huntr.com/bounties/a9951bca-9bd8-49b2-b143-4cd4219f9fa0 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*

History

02 Apr 2025, 16:07

Type Values Removed Values Added
References () https://huntr.com/bounties/a9951bca-9bd8-49b2-b143-4cd4219f9fa0 - () https://huntr.com/bounties/a9951bca-9bd8-49b2-b143-4cd4219f9fa0 - Exploit, Third Party Advisory
First Time Ollama
Ollama ollama
CPE cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad en ollama/ollama versiones anteriores a la 0.3.14 permite a un usuario malintencionado cargar y crear un archivo de modelo GGUF personalizado en el servidor Ollama. Esto puede provocar un error de división por cero en la función ggufPadding, lo que provoca el bloqueo del servidor y un ataque de denegación de servicio (DoS).

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-04-02 16:07


NVD link : CVE-2025-0317

Mitre link : CVE-2025-0317

CVE.ORG link : CVE-2025-0317


JSON object : View

Products Affected

ollama

  • ollama
CWE
CWE-369

Divide By Zero