Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0317

Опубликовано: 20 мар. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Service (DoS) attack.

A flaw was found in Ollama. This vulnerability allows a malicious user to upload and create a customized GGUF model file on the Ollama server, leading to a division by zero error in the ggufPadding function. This causes the server to crash, resulting in a denial of service (DoS) attack.

Отчет

Ansible LightSpeed does not use Ollama server. The library is included in the image just for local development or testing.

Меры по смягчению последствий

Implementing an input validation to check a valid model file formats before processing would help to mitigate this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2353587ollama: Divide By Zero in ollama/ollama

EPSS

Процентиль: 61%
0.00414
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
10 месяцев назад

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Service (DoS) attack.

CVSS3: 7.5
debian
10 месяцев назад

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious ...

CVSS3: 7.5
github
10 месяцев назад

Ollama Divide By Zero vulnerability

EPSS

Процентиль: 61%
0.00414
Низкий

7.5 High

CVSS3