CVE-2024-39720Patch(ollama / ollama)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ollama ollama systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ollama

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ollama

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 105-11
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical out-of-bounds read vulnerability (CVE-2024-39720) discovered in Ollama AI framework. Update to version 0.1.46 to mitigate risks. Link: https://thedailytechfeed.com/critical-vulnerabilities-in-ollama-ai-framework-expose-systems-to-attacks-update-urged/ #CVE #Ollama #AI #Security #Vulnerability #Exploit #Patch #Update #Framework #Systems #Attack #Risk #Mitigation #Software #Infosec #Threat #Exposure #Bug #Protection #Version

    Post summary

    A critical out-of-bounds read vulnerability (CVE‑2024‑39720) has been discovered in the Ollama AI framework, with a mitigation recommendation to update to version 0.1.46.

    0000074
    322 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appollamaollama---

Explore more