Bug 2035037 (CVE-2021-41495)

Summary: CVE-2021-41495 numpy: NULL pointer dereference in numpy.sort in in the PyArray_DescrNew() due to missing return-value validation
Product: [Other] Security Response Reporter: Guilherme de Almeida Suckevicz <gsuckevi>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: cstratak, dbecker, gwync, hhorak, jjoyce, jorton, jschluet, jspaleta, j, jwong, kaycoth, lhh, lpeer, manisandro, mburns, mmuzila, nforro, nobody, orion, osoukup, python-maint, rdieter, sclewis, slinaber, TicoTimo, tomspur
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-12-10 00:13:26 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2035038, 2035039, 2035448, 2035449, 2037379, 2037380, 2037381, 2037382, 2037383, 2037384, 2037385    
Bug Blocks: 2035045    

Description Guilherme de Almeida Suckevicz 2021-12-22 19:01:54 UTC
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays.

Reference:
https://github.com/numpy/numpy/issues/19038

Comment 1 Guilherme de Almeida Suckevicz 2021-12-22 19:02:13 UTC
Created python2-numpy tracking bugs for this issue:

Affects: epel-7 [bug 2035038]


Created python3-numpy tracking bugs for this issue:

Affects: epel-7 [bug 2035039]

Comment 6 errata-xmlrpc 2022-12-07 19:25:41 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.2

Via RHSA-2022:8852 https://access.redhat.com/errata/RHSA-2022:8852

Comment 7 errata-xmlrpc 2022-12-07 20:26:15 UTC
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 16.1

Via RHSA-2022:8861 https://access.redhat.com/errata/RHSA-2022:8861

Comment 8 Product Security DevOps Team 2022-12-10 00:13:24 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-41495