PT-2025-12311 · Ollama · Ollama
Published
2025-03-20
·
Updated
2025-04-02
·
CVE-2025-0315
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ollama/ollama versions 0.3.14 and earlier
Description
A malicious user can create a customized GGUF model file, upload it to the Ollama server, and create it, causing the server to allocate unlimited memory. This leads to a Denial of Service (DoS) attack.
Recommendations
For versions 0.3.14 and earlier, consider restricting access to the model file upload feature to prevent malicious users from uploading customized GGUF model files until a patch is available. As a temporary workaround, monitor server memory allocation closely to detect and mitigate potential DoS attacks.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ollama