Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4473 | Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library. |
Github GHSA |
GHSA-fpmr-m242-xm7x | Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7183868 |
|
Thu, 19 Jun 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm qiskit |
|
| CPEs | cpe:2.3:a:ibm:qiskit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm qiskit |
Fri, 21 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Feb 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library. | |
| Title | Qiskit SDK denial of service | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-26T19:48:05.242Z
Reserved: 2025-02-17T19:37:50.068Z
Link: CVE-2025-1403
Updated: 2025-02-21T17:10:54.264Z
Status : Analyzed
Published: 2025-02-21T17:15:13.437
Modified: 2025-09-30T15:25:51.423
Link: CVE-2025-1403
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA