Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7183868 |
![]() ![]() |
History
Fri, 21 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 21 Feb 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library. | |
Title | Qiskit SDK denial of service | |
Weaknesses | CWE-502 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-02-21T17:11:02.240Z
Reserved: 2025-02-17T19:37:50.068Z
Link: CVE-2025-1403

Updated: 2025-02-21T17:10:54.264Z

Status : Received
Published: 2025-02-21T17:15:13.437
Modified: 2025-02-21T18:15:20.550
Link: CVE-2025-1403

No data.