A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause of the issue is an out-of-bounds read in the gguf.go file.
| Software | From | Fixed in |
|---|---|---|
github.com/ollama/ollama
|
- | 0.3.14.x |
| ollama / ollama | - | 0.3.14.x |