Skip to content
scikit-learnGHSA-jxfp-4rvq-9h9m

scikit-learn Denial of Service

High7.5CVE-2020-28975 · Published May 24, 2022 · updated Dec 3, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
scikit-learn
PyPI
>= 0.23.2, < 1.0.11.0.1
Details and references

svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted model SVM (introduced via pickle, json, or any other model permanence standard) with a large value in the _n_support array. NOTE: the scikit-learn vendor's position is that the behavior can only occur if the library's API is violated by an application that changes a private attribute.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Also known as
CVE-2020-28975, PYSEC-2020-108

More scikit-learn advisories

All scikit-learn
DateAdvisory
May 242022scikit-learn Deserialization of Untrusted Data
CVE-2020-13092Critical9.8no fix yet
Jun 62024scikit-learn sensitive data leakage vulnerability
CVE-2024-5206Medium5.3fixed in 1.5.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.