REDHAT-BUG-2221034: Use After Free
DISPUTED A use-after-free issue was discovered in PyFindObjects() function in SciPy versions prior to 1.8.0.
https://github.com/scipy/scipy/issues/14713 http://www.square16.org/achievement/cve-2023-29824/ https://github.com/scipy/scipy/pull/15013 https://github.com/scipy/scipy/issues/14713#issuecomment-1629468565
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2221034?
The severity of REDHAT-BUG-2221034 is currently disputed, but it relates to a use-after-free vulnerability.
Which versions of SciPy are affected by REDHAT-BUG-2221034?
SciPy versions prior to 1.8.0 are affected by the vulnerability described in REDHAT-BUG-2221034.
How do I fix REDHAT-BUG-2221034?
To mitigate REDHAT-BUG-2221034, it is recommended to upgrade to SciPy version 1.8.0 or later.
What is a use-after-free vulnerability in REDHAT-BUG-2221034?
A use-after-free vulnerability, like REDHAT-BUG-2221034, occurs when a program continues to use memory after it has been freed, potentially leading to crashes or security exploits.
Is there a patch available for REDHAT-BUG-2221034?
Yes, the patch for REDHAT-BUG-2221034 is included in SciPy version 1.8.0 and later.