vulnerability

SUSE: CVE-2024-39720: SUSE Linux Security Advisory

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:C)
Published
Nov 8, 2024
Added
Dec 5, 2025
Modified
Dec 5, 2025

Description

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes starting with the GGUF custom magic header. By leveraging a custom Modelfile that includes a FROM statement pointing to the attacker-controlled blob file, the attacker can crash the application through the CreateModel route, leading to a segmentation fault (signal SIGSEGV: segmentation violation).

Solution

suse-upgrade-govulncheck-vulndb
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.