CVE-2023-25399
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function.
02 / AFFECTED SOFTWARE
Affected packages
6 explicit affected versions
69 explicit affected versions
69 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
## Withdrawn Advisory This advisory has been withdrawn because it has been found to not be an issue. Please see the issue [here](https://github.com/scipy/scipy/issues/16235#issuecomment-1625361328) for more information. ## Original Description A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in `Py_FindObjects()` function.
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function.
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.
05 / REFERENCES
Further evidence
- http://www.square16.org/achievement/cve-2023-25399
- https://github.com/pypa/advisory-database/tree/main/vulns/scipy/PYSEC-2023-102.yaml
- https://github.com/scipy/scipy
- https://github.com/scipy/scipy/commit/9b6521198c4f31d3f9cb525e581bea8e3e77f0a2
- https://github.com/scipy/scipy/issues/16235
- https://github.com/scipy/scipy/issues/16235#issuecomment-1625361328
- https://github.com/scipy/scipy/pull/16397
- https://nvd.nist.gov/vuln/detail/CVE-2023-25399
- http://www.square16.org/achievement/cve-2023-25399/
- https://github.com/advisories/GHSA-9jx5-6pgf-crrp
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25399.json