PT-2025-12312 · Ollama · Ollama

Published

2025-03-20

·

Updated

2025-07-10

·

CVE-2025-0317

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ollama/ollama versions prior to 0.3.14
Description A malicious user can upload and create a customized GGUF model file on the Ollama server, leading to a division by zero error in the ggufPadding function. This error causes the server to crash, resulting in a Denial of Service (DoS) attack.
Recommendations For versions prior to 0.3.14, update to version 0.3.14 or later to resolve the issue. As a temporary workaround, consider disabling the ggufPadding function until a patch is available. Restrict access to the GGUF model file upload feature to minimize the risk of exploitation.

Exploit

Fix

DoS

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0317
GHSA-9GCR-28RP-CC24
GO-2025-3559
OPENSUSE-SU-2025:14955-1

Affected Products

Ollama