Memory leak in Scipy - CVE-2023-25399

 

Memory leak in Scipy - CVE-2023-25399

Published: July 16, 2023


Vulnerability identifier: #VU78289
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25399
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform DoS attack on the target system.

The vulnerability exists due memory leak within the Py_FindObjects() function. A local user can force the application to leak memory and perform denial of service attack.


Affected software

Scipy
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
HPC Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
Python for Scientific Computing
Oracle Business Intelligence Enterprise Edition
Robotic Process Automation for Cloud Pak
python3-scipy (Ubuntu package)
python-scipy-debuginfo
python-scipy_1_2_0-gnu-hpc-debuginfo
python3-scipy_1_2_0-gnu-hpc-debuginfo
python3-scipy_1_2_0-gnu-hpc
python-scipy_1_2_0-gnu-hpc-debugsource
python3-scipy
python2-scipy
scipy-debugsource
scipy-debuginfo
scipy
python3-scipy_1_3_3-gnu-hpc-debuginfo
python3-scipy-gnu-hpc
python-scipy_1_3_3-gnu-hpc-debugsource
python3-scipy_1_3_3-gnu-hpc
python-scipy-debugsource
python3-scipy-debuginfo
App Connect Enterprise Certified Container
IBM Maximo Application Suite
IBM Business Automation Workflow

How to mitigate CVE-2023-25399

Install updates from vendor's website.

Scipy - update to 1.11.1
Python for Scientific Computing - update to 4.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10
python3-scipy (Ubuntu package) - addressed in versions Ubuntu Pro, 1.8.1-10ubuntu0.22.10.1
python-scipy-debuginfo - update to 1.2.0-150100.4.6.1
python-scipy_1_2_0-gnu-hpc-debuginfo - update to 1.2.0-150100.4.6.1
python3-scipy_1_2_0-gnu-hpc-debuginfo - update to 1.2.0-150100.4.6.1
python3-scipy_1_2_0-gnu-hpc - update to 1.2.0-150100.4.6.1
python-scipy_1_2_0-gnu-hpc-debugsource - update to 1.2.0-150100.4.6.1
python3-scipy - update to 1.2.2-4
python2-scipy - update to 1.2.2-4
scipy-debugsource - update to 1.2.2-4
scipy-debuginfo - update to 1.2.2-4
scipy - update to 1.2.2-4
python3-scipy_1_3_3-gnu-hpc-debuginfo - update to 1.3.3-150200.5.3.1
python3-scipy-gnu-hpc - update to 1.3.3-150200.5.3.1
python-scipy_1_3_3-gnu-hpc-debugsource - update to 1.3.3-150200.5.3.1
python3-scipy_1_3_3-gnu-hpc - update to 1.3.3-150200.5.3.1
python-scipy-debugsource - update to 1.3.3-150200.5.3.1
python3-scipy-debuginfo - update to 1.3.3-150200.5.3.1
python3-scipy - update to 1.3.3-150200.5.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.3, 7.1.0
IBM Maximo Application Suite - update to 8.11.1
IBM Business Automation Workflow - update to 23.0.2 IF001

External References

Related Security Bulletins