ollama

Patched
Data & ML from mirror.gcr.io/ollama/ollama
Pull Reference
ghcr.io/verity-org/ollama/ollama
docker pull ghcr.io/verity-org/ollama/ollama
Available Versions
0.24.0 latest 27 CVEs fixed 22 remaining
0.23.4 27 CVEs fixed 22 remaining
0.23.3 27 CVEs fixed 22 remaining
Copa-Patched Image

Patched in-place from the upstream image using Copa . OS-level vulnerabilities are fixed without rebuilding \u2014 same layers, same behavior, fewer CVEs.

Signed SLSA L3 SBOM Rekor
Verify this artifact
Cosign signature
cosign verify \
  --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  ghcr.io/verity-org/ollama/ollama:0.24.0
Build provenance
gh attestation verify \
  oci://ghcr.io/verity-org/ollama/ollama:0.24.0 \
  --owner verity-org

Vulnerability Scan

Found 49 vulnerabilit ies in the original image. 27 fixed by Copa. 22 remaining after patching.

12HIGH29MEDIUM8LOW

Awaiting upstream fix

No fix is available yet for these vulnerabilities.

IDPackageInstalledFixedSeverity
CVE-2026-27456bsdutils1:2.39.3-9ubuntu6.5 MEDIUM
CVE-2026-27456libblkid12.39.3-9ubuntu6.5 MEDIUM
CVE-2026-4046libc-bin2.39-0ubuntu8.7 MEDIUM
CVE-2026-4437libc-bin2.39-0ubuntu8.7 MEDIUM
CVE-2026-4438libc-bin2.39-0ubuntu8.7 MEDIUM
CVE-2026-4046libc62.39-0ubuntu8.7 MEDIUM
CVE-2026-4437libc62.39-0ubuntu8.7 MEDIUM
CVE-2026-4438libc62.39-0ubuntu8.7 MEDIUM
CVE-2025-66382libexpat12.6.1-2ubuntu0.4 MEDIUM
CVE-2026-27456libmount12.39.3-9ubuntu6.5 MEDIUM
CVE-2026-27456libsmartcols12.39.3-9ubuntu6.5 MEDIUM
CVE-2026-27456libuuid12.39.3-9ubuntu6.5 MEDIUM
CVE-2026-27456mount2.39.3-9ubuntu6.5 MEDIUM
CVE-2025-45582tar1.35+dfsg-3build1 MEDIUM
CVE-2026-5704tar1.35+dfsg-3build1 MEDIUM
CVE-2026-27456util-linux2.39.3-9ubuntu6.5 MEDIUM
CVE-2025-1352libelf1t640.190-1.1ubuntu0.1 LOW
CVE-2025-1376libelf1t640.190-1.1ubuntu0.1 LOW
CVE-2024-2236libgcrypt201.10.3-2build1 LOW
CVE-2025-5222libicu7474.2-1ubuntu3.1 LOW
CVE-2024-56433login1:4.13+dfsg1-4ubuntu3.2 LOW
CVE-2024-56433passwd1:4.13+dfsg1-4ubuntu3.2 LOW
Source
Copa (in-place patch)
Platforms
linux/amd64, linux/arm64
Registry
ghcr.io/verity-org
Upstream
mirror.gcr.io/ollama/ollama
Version
0.24.0