Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5757

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

A flaw was found in Ollama's model quantization engine. An unauthenticated remote attacker can exploit this vulnerability to read and exfiltrate the server's heap memory. This could lead to sensitive data exposure, further compromise of the system, and allow for stealthy persistence within the environment.

Отчет

An Important information disclosure flaw in Ollama's model quantization engine allows unauthenticated remote attackers to exfiltrate server heap memory, potentially leading to sensitive data exposure. This vulnerability is rated Important due to the potential for remote exploitation without authentication.

Меры по смягчению последствий

To mitigate this vulnerability, restrict network access to the Ollama service. Configure firewall rules to limit access to trusted networks or localhost only. If the Ollama service is running, a restart may be required for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Not affected
Red Hat build of Debezium 3debezium-ai-embeddings-ollamaNot affected
Red Hat build of Debezium 3langchain4j-ollamaNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Not affected
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2493588Ollama: Information disclosure vulnerability in model quantization engine

EPSS

Процентиль: 42%
0.00551
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

CVSS3: 7.5
debian
около 1 месяца назад

Unauthenticated remote information disclosure vulnerability in Ollama' ...

CVSS3: 7.5
github
около 1 месяца назад

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

EPSS

Процентиль: 42%
0.00551
Низкий

7.5 High

CVSS3