CVE-2021-41495NULL Pointer Dereference in Numpy

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 71.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateDec 7

Description

Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory ex

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages6 packages

PyPInumpy/numpy< 1.19+1
Ubuntunumpy/numpy< 1:1.17.4-5ubuntu3.1+1
NVDnumpy/numpy1.19.0
debiandebian/numpy

🔴Vulnerability Details

5
OSV
numpy vulnerabilities2022-12-07
OSV
NumPy NULL Pointer Dereference2022-02-08
GHSA
NumPy NULL Pointer Dereference2022-02-08
OSV
CVE-2021-41495: Null Pointer Dereference vulnerability exists in numpy2021-12-17
OSV
CVE-2021-41495: Null Pointer Dereference vulnerability exists in numpy2021-12-17

📋Vendor Advisories

5
Ubuntu
NumPy vulnerabilities2022-12-07
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Database - Machine Learning (Numpy) — CVE-2021-414952022-10-15
Microsoft
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-value validation which allows attackers to conduct DoS attacks 2021-12-14
Red Hat
numpy: NULL pointer dereference in numpy.sort in in the PyArray_DescrNew() due to missing return-value validation2021-05-19
Debian
CVE-2021-41495: numpy - Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.1...2021

🕵️Threat Intelligence

1
Tenable
Oracle July 2022 Critical Patch Update Addresses 188 CVEs2022-07-20

📄Research Papers

1
arXiv
Threat Assessment in Machine Learning based Systems2022-06-30