GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.
CVSS Details
- CVSS 3.1 Base Score: 3.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-gslamazon-linux-ami-2-upgrade-gsl-debuginfoamazon-linux-ami-2-upgrade-gsl-devel | Feb 26, 2025 | Oct 27, 2024 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-gslamazon-linux-2023-upgrade-gsl-debuginfoamazon-linux-2023-upgrade-gsl-debugsourceamazon-linux-2023-upgrade-gsl-devel | Feb 26, 2025 | Oct 27, 2024 | |
| Debian | no-fix-debian-deb-package | May 15, 2025 | Oct 27, 2024 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub