CVE-2025-1403

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-1403
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1403.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-1403
Aliases
Published
2025-02-21T17:15:13Z
Modified
2025-06-19T03:20:25Z
Summary
[none]
Details

Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.

References

Affected packages

Git / github.com/qiskit/qiskit

Affected ranges

Type
GIT
Repo
https://github.com/qiskit/qiskit
Events