Memory leak in Scipy - CVE-2023-25399
Published: July 16, 2023
Vulnerability identifier: #VU78289
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25399
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform DoS attack on the target system.
The vulnerability exists due memory leak within the Py_FindObjects() function. A local user can force the application to leak memory and perform denial of service attack.
Affected software
Scipy
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
HPC Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
Python for Scientific Computing
Oracle Business Intelligence Enterprise Edition
Robotic Process Automation for Cloud Pak
python3-scipy (Ubuntu package)
python-scipy-debuginfo
python-scipy_1_2_0-gnu-hpc-debuginfo
python3-scipy_1_2_0-gnu-hpc-debuginfo
python3-scipy_1_2_0-gnu-hpc
python-scipy_1_2_0-gnu-hpc-debugsource
python3-scipy
python2-scipy
scipy-debugsource
scipy-debuginfo
scipy
python3-scipy_1_3_3-gnu-hpc-debuginfo
python3-scipy-gnu-hpc
python-scipy_1_3_3-gnu-hpc-debugsource
python3-scipy_1_3_3-gnu-hpc
python-scipy-debugsource
python3-scipy-debuginfo
App Connect Enterprise Certified Container
IBM Maximo Application Suite
IBM Business Automation Workflow
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
HPC Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
Python for Scientific Computing
Oracle Business Intelligence Enterprise Edition
Robotic Process Automation for Cloud Pak
python3-scipy (Ubuntu package)
python-scipy-debuginfo
python-scipy_1_2_0-gnu-hpc-debuginfo
python3-scipy_1_2_0-gnu-hpc-debuginfo
python3-scipy_1_2_0-gnu-hpc
python-scipy_1_2_0-gnu-hpc-debugsource
python3-scipy
python2-scipy
scipy-debugsource
scipy-debuginfo
scipy
python3-scipy_1_3_3-gnu-hpc-debuginfo
python3-scipy-gnu-hpc
python-scipy_1_3_3-gnu-hpc-debugsource
python3-scipy_1_3_3-gnu-hpc
python-scipy-debugsource
python3-scipy-debuginfo
App Connect Enterprise Certified Container
IBM Maximo Application Suite
IBM Business Automation Workflow
How to mitigate CVE-2023-25399
Install updates from vendor's website.
Scipy - update to 1.11.1
Python for Scientific Computing - update to 4.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10
python3-scipy (Ubuntu package) - addressed in versions Ubuntu Pro, 1.8.1-10ubuntu0.22.10.1
python-scipy-debuginfo - update to 1.2.0-150100.4.6.1
python-scipy_1_2_0-gnu-hpc-debuginfo - update to 1.2.0-150100.4.6.1
python3-scipy_1_2_0-gnu-hpc-debuginfo - update to 1.2.0-150100.4.6.1
python3-scipy_1_2_0-gnu-hpc - update to 1.2.0-150100.4.6.1
python-scipy_1_2_0-gnu-hpc-debugsource - update to 1.2.0-150100.4.6.1
python3-scipy - update to 1.2.2-4
python2-scipy - update to 1.2.2-4
scipy-debugsource - update to 1.2.2-4
scipy-debuginfo - update to 1.2.2-4
scipy - update to 1.2.2-4
python3-scipy_1_3_3-gnu-hpc-debuginfo - update to 1.3.3-150200.5.3.1
python3-scipy-gnu-hpc - update to 1.3.3-150200.5.3.1
python-scipy_1_3_3-gnu-hpc-debugsource - update to 1.3.3-150200.5.3.1
python3-scipy_1_3_3-gnu-hpc - update to 1.3.3-150200.5.3.1
python-scipy-debugsource - update to 1.3.3-150200.5.3.1
python3-scipy-debuginfo - update to 1.3.3-150200.5.3.1
python3-scipy - update to 1.3.3-150200.5.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.3, 7.1.0
IBM Maximo Application Suite - update to 8.11.1
IBM Business Automation Workflow - update to 23.0.2 IF001
Python for Scientific Computing - update to 4.2.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10
python3-scipy (Ubuntu package) - addressed in versions Ubuntu Pro, 1.8.1-10ubuntu0.22.10.1
python-scipy-debuginfo - update to 1.2.0-150100.4.6.1
python-scipy_1_2_0-gnu-hpc-debuginfo - update to 1.2.0-150100.4.6.1
python3-scipy_1_2_0-gnu-hpc-debuginfo - update to 1.2.0-150100.4.6.1
python3-scipy_1_2_0-gnu-hpc - update to 1.2.0-150100.4.6.1
python-scipy_1_2_0-gnu-hpc-debugsource - update to 1.2.0-150100.4.6.1
python3-scipy - update to 1.2.2-4
python2-scipy - update to 1.2.2-4
scipy-debugsource - update to 1.2.2-4
scipy-debuginfo - update to 1.2.2-4
scipy - update to 1.2.2-4
python3-scipy_1_3_3-gnu-hpc-debuginfo - update to 1.3.3-150200.5.3.1
python3-scipy-gnu-hpc - update to 1.3.3-150200.5.3.1
python-scipy_1_3_3-gnu-hpc-debugsource - update to 1.3.3-150200.5.3.1
python3-scipy_1_3_3-gnu-hpc - update to 1.3.3-150200.5.3.1
python-scipy-debugsource - update to 1.3.3-150200.5.3.1
python3-scipy-debuginfo - update to 1.3.3-150200.5.3.1
python3-scipy - update to 1.3.3-150200.5.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.3, 7.1.0
IBM Maximo Application Suite - update to 8.11.1
IBM Business Automation Workflow - update to 23.0.2 IF001
External References
Related Security Bulletins
- Memory leak in SciPy
- Ubuntu update for scipy
- Memory leak in IBM App Connect Enterprise Certified Container
- SUSE update for python-scipy
- SUSE update for python-scipy
- IBM Robotic Process Automation for Cloud Pak update for SciPy
- Multiple vulnerabilities in IBM Business Automation Workflow
- Memory leak in IBM Maximo Application Suite - Monitor Component
- openEuler update for scipy
- Splunk Python for Scientific Computing update for third-party packages
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition