CVE-2024-8063
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.62%
- CWE
- CWE-369
- Published
- 2025-03-20
- Last modified
- 2026-03-13
Affected products
- ollama ollama/ollama
Weakness type
Related vulnerabilities
- CVE-2021-32494 — Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create m
- CVE-2026-24826 — Out-of-bounds write in turso3d
- CVE-2025-4637 — Divide By Zero in dlib
- CVE-2023-3896 — A divide by zero issue existed in vim of OpenCloudOS Stream
- CVE-2024-4785 — BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
- CVE-2019-5637 — Beckhoff TwinCAT Profinet Driver Divide-by-Zero Denial of Service
- CVE-2025-54581 — vproxy is vulnerable to a divide by zero DoS attack
- CVE-2025-23321 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero