A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Service (DoS) attack.
{
"severity": "HIGH",
"github_reviewed_at": "2025-03-22T00:01:44Z",
"cwe_ids": [
"CWE-369"
],
"nvd_published_at": "2025-03-20T10:15:52Z",
"github_reviewed": true
}