GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00028}

epss

{'score': 0.0003}


Wed, 30 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Gnu
Gnu gnu Scientific Library
CPEs cpe:2.3:a:gnu:gnu_scientific_library:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu gnu Scientific Library
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 01:45:00 +0000

Type Values Removed Values Added
Title gsl: integer overflow in gsl/siman/siman.c
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}

threat_severity

Low


Sun, 27 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
Description GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-30T18:13:40.086Z

Reserved: 2024-10-27T00:00:00

Link: CVE-2024-50610

cve-icon Vulnrichment

Updated: 2024-10-30T18:13:31.478Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-27T22:15:03.473

Modified: 2025-09-04T16:43:48.460

Link: CVE-2024-50610

cve-icon Redhat

Severity : Low

Publid Date: 2024-10-27T00:00:00Z

Links: CVE-2024-50610 - Bugzilla

cve-icon OpenCVE Enrichment

No data.