Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-4473 Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.
Github GHSA Github GHSA GHSA-fpmr-m242-xm7x Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 19 Jun 2025 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm qiskit
CPEs cpe:2.3:a:ibm:qiskit:*:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm qiskit

Fri, 21 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Feb 2025 17:00:00 +0000

Type Values Removed Values Added
Description Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.
Title Qiskit SDK denial of service
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-26T19:48:05.242Z

Reserved: 2025-02-17T19:37:50.068Z

Link: CVE-2025-1403

cve-icon Vulnrichment

Updated: 2025-02-21T17:10:54.264Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-21T17:15:13.437

Modified: 2025-09-30T15:25:51.423

Link: CVE-2025-1403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.