CVE-2025-0315: Allocation of Resources Without Limits or Throttling in ollama/ollama
Published Mar 20, 2025
·Updated
A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) attack.
Affected Software
3 affected components
Ollama Ollama<=0.3.14
go/github.com/ollama/ollama<=0.3.14
Ollama Ollama<=0.3.14
Event History
Mar 20, 2025
CVE Published
via MITRE·10:09 AM
Data Sourced
via MITRE·10:09 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-0315?
CVE-2025-0315 has a high severity due to its potential to cause a Denial of Service (DoS) attack.
2
How do I fix CVE-2025-0315?
To fix CVE-2025-0315, upgrade to a version of Ollama greater than 0.3.14.
3
What kind of attack does CVE-2025-0315 enable?
CVE-2025-0315 allows for a Denial of Service (DoS) attack through unlimited memory allocation.
4
Who is affected by CVE-2025-0315?
Users of Ollama version 0.3.14 and below are affected by CVE-2025-0315.
5
What product is involved in CVE-2025-0315?
CVE-2025-0315 involves the Ollama server software.