A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade scipy | Jul 30, 2024 | Jul 5, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python3-scipy | Jan 10, 2024 | Jul 5, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade python3-scipy | Jan 10, 2024 | Jul 5, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python2-scipy | Jan 10, 2024 | Jul 5, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-scipy | Jan 10, 2024 | Jul 5, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 5, 2023 |
| Suse | — | Upgrade python3-scipy_1_3_3-gnu-hpcUpgrade python3-scipy_1_2_0-gnu-hpcUpgrade python3-scipy-gnu-hpcUpgrade python3-scipy | Jul 26, 2023 | Jul 5, 2023 |
| Ubuntu | — | Upgrade python3-scipyUpgrade python3-scipy (Ubuntu Pro) | Jul 14, 2023 | Jul 5, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub