Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) – Overview and Mitigations
ID: f26b48e4-31fa-5fc8-a51d-31b6183ef7ca
STIX ID: report--f26b48e4-31fa-5fc8-a51d-31b6183ef7ca
Feed Name: Wiz Blog
Wiz Research discovered CVE-2024-37032 (“Probllama”), a critical remote-code-execution vulnerability in the Ollama AI server where a crafted model manifest 'digest' allows path traversal leading to arbitrary file writes/reads and RCE—particularly severe in Docker installations that run the server as root and bind to 0.0.0.0. The report details the technical root cause, exploitation chain (including corrupting /etc/ld.so.preload to achieve code execution), evidence of over 1,000 internet-exposed vulnerable instances, and remediation guidance (upgrade to Ollama 0.1.34+, avoid exposing instances without authentication/reverse-proxy).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
