Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0317

Опубликовано: 20 мар. 2025
Источник: redhat
CVSS3: 7.5

Описание

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Service (DoS) attack.

A flaw was found in Ollama. This vulnerability allows a malicious user to upload and create a customized GGUF model file on the Ollama server, leading to a division by zero error in the ggufPadding function. This causes the server to crash, resulting in a denial of service (DoS) attack.

Отчет

Ansible LightSpeed does not use Ollama server. The library is included in the image just for local development or testing.

Меры по смягчению последствий

Implementing an input validation to check a valid model file formats before processing would help to mitigate this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2353587ollama: Divide By Zero in ollama/ollama

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Service (DoS) attack.

CVSS3: 7.5
debian
11 месяцев назад

A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious ...

CVSS3: 7.5
github
11 месяцев назад

Ollama Divide By Zero vulnerability

7.5 High

CVSS3