Junglewise Threat Intelligence

CVE-2021-41495: PYSEC-2021-856 - Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-val

CVE-2021-41495 · Severity: low · CVSS 3.1 · Published 2021-12-17

Vendors: PyPI.

Executive brief

Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays.

Affected products

  • PyPI numpy

Related threats