REDHAT-BUG-1667950: Medium severity numpy vulnerability
An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call.
Upstream issue: https://github.com/numpy/numpy/issues/12759
Upstream patch: https://github.com/numpy/numpy/commit/a2bd3a7eabfe053d6d16a2130fdcad9e5211f6bb
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1667950?
REDHAT-BUG-1667950 is considered a critical vulnerability due to the potential for remote code execution.
How do I fix REDHAT-BUG-1667950?
To fix REDHAT-BUG-1667950, upgrade NumPy to version 1.16.1 or later where the vulnerability has been addressed.
Who is affected by REDHAT-BUG-1667950?
Users of NumPy version 1.16.0 and earlier are affected by REDHAT-BUG-1667950.
What type of attack can REDHAT-BUG-1667950 facilitate?
REDHAT-BUG-1667950 can facilitate remote code execution attacks via maliciously crafted serialized objects.
When was REDHAT-BUG-1667950 reported?
REDHAT-BUG-1667950 was reported in 2020, highlighting vulnerabilities in NumPy versions prior to 1.16.1.