{"id":"CVE-2025-15514","title":"Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality","summary":"Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the applicat…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-395"],"vendor":"ollama","product":"ollama","affected":["ollama >= 0.11.6, <= 0.13.5","ollama = 0.11.5"],"published":"2026-01-12","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15514","references":[{"url":"https://https://github.com/ollama/ollama","label":"disclosure@vulncheck.com"},{"url":"https://huntr.com/bounties/172df98b-07cd-41ea-a628-366f8cd525c0","label":"disclosure@vulncheck.com"},{"url":"https://ollama.com/","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ollama-multi-modal-image-processing-null-pointer-dereference","label":"disclosure@vulncheck.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-15514","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2428828","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15514.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-15514"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15514"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"epss":0.00776,"epssPercentile":0.54342,"ingestedAt":"2026-06-30T13:26:50.448Z","exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-01-13T17:19:51.008013Z"},"scores":{"nvd":7.5,"cna":8.7,"vendor":7.5},"slug":"CVE-2025-15514","body":"## Overview\n\nOllama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the application fails to validate that the decoded data represents valid media before passing it to the mtmd_helper_bitmap_init_from_buf function. This function can return NULL for malformed input, but the code does not check this return value before dereferencing the pointer in subsequent operations. A remote attacker can exploit this by sending specially crafted base64 image data that decodes to invalid media, causing a segmentation fault and crashing the runner process. This results in a denial of service condition where the model becomes unavailable to all users until the service is restarted.\n\n## Affected\n\n- `ollama >= 0.11.6, <= 0.13.5`\n- `ollama = 0.11.5`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat OpenShift AI (RHOAI) · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15514.json)","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":204865,"id":"CVE-2025-15514","ts":1789563356965,"field":"exploit_available","old":"false","new":"true"}]}