Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8063

Опубликовано: 20 мар. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for block_count in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.

A flaw was found in Ollama. This vulnerability allows a denial of service (DoS) via a crafted Modelfile containing a specific type for block_count when importing GGUF models, leading to a server crash.

Отчет

Ansible LightSpeed does not use Ollama server. The library is included in the image just for local development or testing.

Меры по смягчению последствий

Implementing an input validation to check a valid model file formats before processing would help to mitigate this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/platform-resource-runner-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/platform-resource-runner-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2353551ollama: Divide by Zero in ollama/ollama

EPSS

Процентиль: 47%
0.00619
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.

CVSS3: 7.5
debian
больше 1 года назад

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. ...

CVSS3: 7.5
github
больше 1 года назад

Ollama Divide by Zero Vulnerability

EPSS

Процентиль: 47%
0.00619
Низкий

7.5 High

CVSS3