HIGH 7.5 PyPI
NumPy NULL Pointer Dereference
GHSA-5545-2q6w-2gh6 · CVE-2021-41495 · PYSEC-2021-856
Published · Modified
Description
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-41495
- WEB https://github.com/numpy/numpy/issues/19038
- ADVISORY https://github.com/advisories/GHSA-5545-2q6w-2gh6
- PACKAGE https://github.com/numpy/numpy
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/numpy/PYSEC-2021-856.yaml
- WEB https://www.oracle.com/security-alerts/cpujul2022.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes