CyberRota Analysis
AI-GeneratedIBM Qiskit SDK versions 2.1.0 to 2.5.1 are vulnerable to a denial of service attack due to improper deserialization of specially crafted objects, which can lead to application crashes. Local attackers can exploit this flaw by sending malicious QPY payloads, resulting in segmentation faults. Organizations utilizing these specific versions of the Qiskit SDK should prioritize patching to mitigate potential disruptions.
Original NVD Description
Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.