An Out-Of-Memory (OOM) vulnerability exists in the ollama
server version 0.3.14. This vulnerability can be triggered when a malicious API server responds with a gzip bomb HTTP response, leading to the ollama
server crashing. The vulnerability is present in the makeRequestWithRetry
and getAuthorizationToken
functions, which use io.ReadAll
to read the response body. This can result in excessive memory usage and a Denial of Service (DoS) condition.
The product does not properly control the allocation and maintenance of a limited resource.
Mitigation of resource exhaustion attacks requires that the target system either:
The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.
The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.