USN-6226-1: SciPy vulnerabilities
It was discovered that SciPy did not properly manage memory operations during reference counting. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-25399) A use-after-free was discovered in SciPy when handling reference counts. An attacker could possibly use this to cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2023-29824)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6226-1?
The severity of USN-6226-1 is critical due to its potential to cause a denial of service.
How do I fix USN-6226-1?
To fix USN-6226-1, update the python3-scipy package to the latest version specified in the advisory for your Ubuntu release.
Which Ubuntu versions are affected by USN-6226-1?
USN-6226-1 affects Ubuntu 22.10, 22.04, and 20.04.
What type of vulnerability is addressed in USN-6226-1?
USN-6226-1 addresses a use-after-free vulnerability related to memory management in SciPy.
Who can exploit the vulnerability in USN-6226-1?
An attacker can potentially exploit the vulnerability in USN-6226-1 to cause a denial of service.