PT-2025-12309 · Ollama · Ollama

Published

2025-03-20

·

Updated

2025-04-04

·

CVE-2025-0312

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ollama/ollama versions prior to 0.3.14
Description The issue allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an unchecked null pointer dereference. This can lead to a Denial of Service (DoS) attack via remote network.
Recommendations For versions prior to 0.3.14, update to version 0.3.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the GGUF model file upload feature to minimize the risk of exploitation.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-0312
GHSA-P2WH-W96X-W232
GO-2025-3582
OPENSUSE-SU-2025:14970-1

Affected Products

Ollama