Home » Database

AVID-2026-R1611

Description

Divide by Zero in ollama/ollama (CVE-2024-8063)

Details

A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for block_count in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.

Reason for inclusion in AVID: CVE-2024-8063 describes a software vulnerability (divide-by-zero) in the Ollama model-serving tool when importing GGUF models, leading to a DoS. This is a software component used in AI model deployment stacks, constituting a supply-chain-relevant issue in general-purpose AI systems. The report provides a clear vulnerability description, impact, and CVSS metadata, supporting its inclusion.

References

Affected or Relevant Artifacts

  • Developer: Meta
  • Deployer: ollama
  • Artifact Details:
TypeName
Systemollama/ollama

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score7.5
Base Severity🔴 High
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability Impact🔴 High

CWE

IDDescription
CWE-369CWE-369 Divide By Zero

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2025-03-20
  • Version: 0.3.3
  • AVID Entry