Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-66960

Опубликовано: 21 янв. 2026
Источник: redhat
CVSS3: 7.5

Описание

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

A flaw was found in ollama. A remote attacker can exploit this vulnerability by providing untrusted GGUF (GGML Unified Format) metadata with a specially crafted string length. This can cause the readGGUFV1String function to improperly process the input, leading to a denial of service, which makes the service unavailable to legitimate users.

Отчет

This vulnerability is rated Moderate for Red Hat products. An issue in ollama allows a remote attacker to cause a denial of service by providing untrusted GGUF metadata. This affects Red Hat Ansible Automation Platform versions 2.4, 2.5, and 2.6, as well as Community Projects including Fedora and Red Hat OpenShift AI.

Меры по смягчению последствий

To reduce the risk of exploitation, ensure that the ollama service processes GGUF metadata only from trusted and verified sources. Avoid loading or processing GGUF files from untrusted or unverified origins.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-130
https://bugzilla.redhat.com/show_bug.cgi?id=2431705ollama: ollama: Denial of Service via untrusted GGUF metadata string length

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

CVSS3: 7.5
debian
2 месяца назад

An issue in ollama v.0.12.10 allows a remote attacker to cause a denia ...

CVSS3: 7.5
github
2 месяца назад

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость функции readGGUFV1String() системы запуска и управления большими языковыми моделями (LLM) Ollama, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3