Executive brief
Ollama is a popular platform for running large language models locally. A vulnerability in how it processes certain model files allows an attacker to crash the Ollama server by providing a specially crafted model configuration. This results in a denial of service, preventing users from accessing or using the AI service until it is restarted.
Technical details
A divide-by-zero vulnerability (CWE-369) exists in Ollama version 0.3.3 and earlier. The flaw is triggered during the import process of GGUF models when a Modelfile contains a crafted value for the 'block_count' parameter. When the server attempts to process this malformed model, it performs a division by zero, leading to an immediate application crash. This can be exploited by a remote attacker without authentication to cause a denial of service (DoS) condition. While the advisory lists version 0.3.3 as affected, later community reports suggest the issue may persist in subsequent versions.
Affected products
- Ollama Ollama <= 0.3.3
Timeline
- 2025-03-20: disclosed: NVD and GitHub Advisory published
- 2024-12-10: other: Issue reported on Ollama GitHub repository