CVE-2023-25399

unknown
Published 2023-07-05 · Modified 2024-05-19
CVSS v3
CVSS v2
VIR risk

Description

A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-25399

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-25399.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed1.10.0-2
debian debianbullseyeaffected
debian debianforkyfixed1.10.0-2
debian debiansidfixed1.10.0-2
debian debiantrixiefixed1.10.0-2

Package impact

EcosystemPackageVulnerableFixed
python PyPIscipy<1.10.01.10.0

References

Verify integrity in audit chain (admin only). AS-IS.