Medium severity5.5NVD Advisory· Published Jul 5, 2023· Updated Jun 17, 2026
CVE-2023-25399
CVE-2023-25399
Description
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
scipyPyPI | < 1.10.0 | 1.10.0 |
Affected products
14- scipy/scipydescription
- ghsa-coords12 versionspkg:pypi/scipypkg:rpm/opensuse/python-scipy&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python-scipy&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python-scipy_1_2_0-gnu-hpc&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python-scipy_1_2_0-gnu-hpc&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python-scipy_1_3_3-gnu-hpc&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python-scipy_1_3_3-gnu-hpc&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/python-scipy&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/python-scipy&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/python-scipy_1_3_3-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/python-scipy_1_3_3-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP5pkg:rpm/suse/python-scipy_1_3_3-gnu-hpc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5
< 1.10.0+ 11 more
- (no CPE)range: < 1.10.0
- (no CPE)range: < 1.2.0-150100.4.6.1
- (no CPE)range: < 1.3.3-150200.5.3.1
- (no CPE)range: < 1.2.0-150100.4.6.1
- (no CPE)range: < 1.2.0-150100.4.6.1
- (no CPE)range: < 1.3.3-150200.5.3.1
- (no CPE)range: < 1.3.3-150200.5.3.1
- (no CPE)range: < 1.3.3-150200.5.3.1
- (no CPE)range: < 1.3.3-150200.5.3.1
- (no CPE)range: < 1.3.3-150200.5.3.1
- (no CPE)range: < 1.3.3-150200.5.3.1
- (no CPE)range: < 1.3.3-150200.5.3.1
Patches
Vulnerability mechanics
References
9- github.com/scipy/scipy/pull/16397nvdPatchWEB
- github.com/scipy/scipy/issues/16235nvdExploitIssue TrackingPatchVendor AdvisoryWEB
- www.square16.org/achievement/cve-2023-25399/nvdThird Party Advisory
- github.com/advisories/GHSA-9jx5-6pgf-crrpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-25399ghsaADVISORY
- www.square16.org/achievement/cve-2023-25399ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/scipy/PYSEC-2023-102.yamlghsaWEB
- github.com/scipy/scipy/commit/9b6521198c4f31d3f9cb525e581bea8e3e77f0a2ghsaWEB
- github.com/scipy/scipy/issues/16235nvdWEB
News mentions
0No linked articles in our index yet.