PT-2025-12217 · Ollama · Ollama

Published

2025-03-20

·

Updated

2025-05-20

·

CVE-2024-8063

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ollama/ollama version v0.3.3
Description A divide by zero issue exists when importing GGUF models with a crafted type for block count in the Modelfile, leading to a denial of service (DoS) condition that causes the server to crash.
Recommendations For version v0.3.3, consider restricting the import of GGUF models or validating the type for block count to prevent the denial of service condition until a patch is available.

Exploit

Fix

Divide By Zero

Weakness Enumeration

Related Identifiers

CVE-2024-8063
GHSA-2XF2-GJM6-G2C6
GO-2025-3689
OPENSUSE-SU-2025:15135-1
PYSEC-2025-144

Affected Products

Ollama