cve/2024/CVE-2024-39721.md
2025-09-29 21:09:30 +02:00

946 B

CVE-2024-39721

Description

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP request is aborted by the client).

POC

Reference

Github