Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12055

Опубликовано: 20 мар. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause of the issue is an out-of-bounds read in the gguf.go file.

A flaw was found in Ollama. This vulnerability allows a malicious user to cause a denial of service (DoS) via a customized gguf model file uploaded to the public Ollama server, which crashes the server when processed.

Отчет

Ansible LightSpeed does not use Ollama server. The library is included in the image just for local development or testing.

Меры по смягчению последствий

Implementing an input validation to check a valid model file formats before processing would help to mitigate this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2353572ollama: DoS using malicious gguf model file in ollama/ollama

EPSS

Процентиль: 46%
0.00232
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause of the issue is an out-of-bounds read in the gguf.go file.

CVSS3: 7.5
debian
11 месяцев назад

A vulnerability in Ollama versions <=0.3.14 allows a malicious user to ...

CVSS3: 7.5
github
11 месяцев назад

Ollama Allows Out-of-Bounds Read

EPSS

Процентиль: 46%
0.00232
Низкий

7.5 High

CVSS3