Database/AI/ML frameworks & serving
Ollama (GGUF import): Crafted GGUF causes DoS on model create
CVSS 7.5CVE-2025-0312AI/ML frameworks & servingcurated
Impact
Crafted GGUF causes DoS on model create
Who can reach it
Customer-supplied GGUF model file
What to do
Upgrade past 0.3.14; GGUF parsing is unhardened C-adjacent code reachable by any model upload
References
Related entries
- NVIDIA Triton (Python backend): Information disclosure from the Python backendCVE-2025-23320 · NVIDIA Triton (Python backend)High
- vLLM (weight loading): `hf_model_weights_iterator` uses `torch.load` without `weights_only`CVE-2025-24357 · vLLM (weight loading)High
- vLLM (ZeroMQ): DoS and data exposure over ZeroMQCVE-2025-30202 · vLLM (ZeroMQ)High
- vLLM (HTTP GET): Single HTTP GET crashes the serverCVE-2025-48956 · vLLM (HTTP GET)High
- PyTorch (`torch.linalg.lu`): DoS on slice operationCVE-2025-55551 · PyTorch (`torch.linalg.lu`)High
- PyTorch (KV/conv path buffer overflow): Buffer overflow when a model combines Conv2d + hardshrink + viewCVE-2025-55558 · PyTorch (KV/conv path buffer overflow)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.