Divide by Zero in ollama/ollama
Published Mar 20, 2025
7.5
HIGHCVSS 3.1
EPSS 0.63%
Description
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=latest
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Ollama | Ollama/ollama | n/a |
|
No data.
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/lightspeed-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/platform-resource-runner-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/lightspeed-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/platform-resource-runner-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/lightspeed-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/platform-resource-runner-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/lightspeed-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/platform-resource-runner-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/platform-resource-runner-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/platform-resource-runner-rhel8 | Not affected | n/a |
github.com/ollama/ollama
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/ollama/ollama | 0 | not fixed |
Remediation
Red Hat statement
Ansible LightSpeed does not use Ollama server. The library is included in the image just for local development or testing.
Red Hat mitigation
Implementing an input validation to check a valid model file formats before processing would help to mitigate this issue.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-8063 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2353551 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-6935 Advisory
- https://github.com/advisories/GHSA-2xf2-gjm6-g2c6 Advisory
- https://github.com/ollama/ollama/issues/8020
- https://github.com/pypa/advisory-database/tree/main/vulns/ollama/PYSEC-2025-144.yaml
- https://huntr.com/bounties/fd8e1ed6-21d2-4c9e-8395-2098f11b7db9 ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-8063
- https://www.cve.org/CVERecord?id=CVE-2024-8063
Change history (0)
No recorded changes yet.