Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
ID: 69a25e86-bd32-5705-8225-2b763dfb19dc
STIX ID: report--69a25e86-bd32-5705-8225-2b763dfb19dc
Feed Name: The Hacker News
Ollama contains a critical GGUF model-loader out-of-bounds read (CVE-2026-7482, 'Bleeding Llama') that can be triggered by uploading a crafted model to /api/create and exfiltrated via /api/push, potentially leaking environment variables, API keys, prompts, and user conversations; additionally, two Windows updater flaws (CVE-2026-42248 and CVE-2026-42249) enable persistent arbitrary code execution when update responses are controlled. Users are advised to apply patches, limit network exposure, disable automatic updates on Windows, and place an authentication proxy or firewall in front of Ollama instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
