Skip to content
OllamaGHSA-95j2-w8x7-hm88

Ollama Out-of-bounds Read

High8.2CVE-2024-39720 · Published Oct 31, 2024 · updated Dec 12, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/ollama/ollama
Go
< 0.1.460.1.46
Details and references

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation).

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-125
Also known as
CVE-2024-39720, GO-2024-3245

More Ollama advisories

All Ollama
DateAdvisory
Aug 292024Ollama can extract members of a ZIP archive outside of the parent directory
CVE-2024-45436High7.5fixed in 0.1.47
Mar 202025Ollama Allows Out-of-Bounds Read
CVE-2024-12055High7.5no fix yet
Mar 202025Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
CVE-2024-12886High7.5no fix yet
Mar 202025Ollama Divide by Zero Vulnerability
CVE-2024-8063High7.5no fix yet
Mar 202025Ollama Divide By Zero vulnerability
CVE-2025-0317High7.5no fix yet
Mar 202025Ollama Allocation of Resources Without Limits or Throttling vulnerability
CVE-2025-0315High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.