Open
Description
Advisory GHSA-2xf2-gjm6-g2c6 references a vulnerability in the following Go modules:
Module |
---|
github.com/ollama/ollama |
Description:
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for block_count
in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.
References:
- ADVISORY: GHSA-2xf2-gjm6-g2c6
- ADVISORY: https://nvd.nist.gov/vuln/detail/CVE-2024-8063
- REPORT: Nancy finds security vulnerabilities ollama/ollama#8020
- WEB: https://huntr.com/bounties/fd8e1ed6-21d2-4c9e-8395-2098f11b7db9
Cross references:
- github.com/ollama/ollama appears in 8 other report(s):
- data/reports/GO-2024-2901.yaml (x/vulndb: potential Go vuln in github.com/ollama/ollama: CVE-2024-37032 #2901)
- data/reports/GO-2024-3104.yaml (x/vulndb: potential Go vuln in github.com/ollama/ollama: CVE-2024-45436 #3104)
- data/reports/GO-2024-3245.yaml (x/vulndb: potential Go vuln in github.com/ollama/ollama: CVE-2024-39720 #3245)
- data/reports/GO-2025-3548.yaml (x/vulndb: potential Go vuln in github.com/ollama/ollama: GHSA-v464-r2r9-www7 #3548)
- data/reports/GO-2025-3557.yaml (x/vulndb: potential Go vuln in github.com/ollama/ollama: GHSA-fccc-8m69-8r78 #3557)
- data/reports/GO-2025-3558.yaml (x/vulndb: potential Go vuln in github.com/ollama/ollama: GHSA-89qx-m49c-8crf #3558)
- data/reports/GO-2025-3559.yaml (x/vulndb: potential Go vuln in github.com/ollama/ollama: GHSA-9gcr-28rp-cc24 #3559)
- data/reports/GO-2025-3582.yaml (x/vulndb: potential Go vuln in github.com/ollama/ollama: GHSA-p2wh-w96x-w232 #3582)
See doc/quickstart.md for instructions on how to triage this report.
id: GO-ID-PENDING
modules:
- module: github.com/ollama/ollama
vulnerable_at: 0.7.0
summary: Ollama Divide by Zero Vulnerability in github.com/ollama/ollama
cves:
- CVE-2024-8063
ghsas:
- GHSA-2xf2-gjm6-g2c6
references:
- advisory: https://github.com/advisories/GHSA-2xf2-gjm6-g2c6
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-8063
- report: https://github.com/ollama/ollama/issues/8020
- web: https://huntr.com/bounties/fd8e1ed6-21d2-4c9e-8395-2098f11b7db9
source:
id: GHSA-2xf2-gjm6-g2c6
created: 2025-05-15T18:01:33.93856887Z
review_status: UNREVIEWED