High severity8.2NVD Advisory· Published Oct 31, 2024· Updated Jun 17, 2026
CVE-2024-39720
CVE-2024-39720
Description
An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/ollama/ollamaGo | < 0.1.46 | 0.1.46 |
Affected products
9- ghsa-coords7 versionspkg:golang/github.com/ollama/ollamapkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Package%20Hub%2012
< 0.1.46+ 6 more
- (no CPE)range: < 0.1.46
- (no CPE)range: < 0.0.20241104T154416-150000.1.12.1
- (no CPE)range: < 0.0.20241104T154416-150000.1.12.1
- (no CPE)range: < 0.0.20241101T215616-1.1
- (no CPE)range: < 0.0.20241104T154416-150000.1.12.1
- (no CPE)range: < 0.0.20241104T154416-150000.1.12.1
- (no CPE)range: < 0.0.20241104T154416-5.1
Patches
Vulnerability mechanics
References
6- oligo.security/blog/more-models-more-probllmsnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-95j2-w8x7-hm88ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-39720ghsaADVISORY
- github.com/ollama/ollama/compare/v0.1.45...v0.1.46nvdProductWEB
- oligosecurity.webflow.io/blog/more-models-more-probllmsghsaWEB
- pkg.go.dev/vuln/GO-2024-3245ghsaWEB
News mentions
0No linked articles in our index yet.