CVE-2024-39720 describes a vulnerability in Ollama versions prior to 0.1.46, where an attacker can crash the application by uploading a specially crafted, malformed GGUF file. This denial-of-service vulnerability has a CVSS score of 8.2 (HIGH), indicating a severe impact on availability (A:H) with low attack complexity (AC:L) and no user interaction required (UI:N). While no active exploits, Metasploit modules, or public exploit code are currently available, the vulnerability allows for remote application crashes via a segmentation fault. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.46CPE matchmatch criteria | cpe:2.3:a:ollama:ollama:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.