The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 15, 2017 |
| Suse | — | Upgrade python-numpy_1_13_3-gnu-hpcUpgrade python3-numpy-gnu-hpcUpgrade python3-numpy-develUpgrade python3-numpy_1_13_3-gnu-hpcUpgrade python-numpy_1_13_3-gnu-hpc-develUpgrade python2-numpyUpgrade python2-numpy-gnu-hpcUpgrade python2-numpy-gnu-hpc-develUpgrade python3-numpy-gnu-hpc-develUpgrade python3-numpyUpgrade python3-numpy_1_13_3-gnu-hpc-develUpgrade python2-numpy-devel | May 20, 2018 | Aug 15, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Aug 15, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 15, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub