
Cloud Vulnerability DB
A community-led vulnerabilities database
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. This vulnerability has been assigned CVE-2023-25399 and is disputed as a bug rather than a vulnerability, as SciPy is not designed to be exposed to untrusted users or data directly (NVD).
The vulnerability stems from a memory management issue in the Py_FindObjects() function where a new reference is returned and assigned to a tuple variable but goes out of scope without decreasing the reference count. The issue has a CVSS v3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Ubuntu).
The vulnerability could potentially lead to memory leaks in the system, which might result in a denial of service condition. However, since SciPy is not designed for exposure to untrusted users or data, the real-world impact is considered limited (NVD).
The issue has been fixed in various Ubuntu releases: Ubuntu 22.10 (1.8.1-10ubuntu0.22.10.1), Ubuntu 22.04 LTS (1.8.0-1exp2ubuntu1+esm1), and Ubuntu 20.04 LTS (1.3.3-3ubuntu0.1~esm1). Users are advised to update their systems to these patched versions (Ubuntu Security Notice).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."