SB2025091583 - Fedora EPEL 10.1 update for python-deepdiff



SB2025091583 - Fedora EPEL 10.1 update for python-deepdiff

Published: September 15, 2025

Security Bulletin ID SB2025091583
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-ID: CVE-2025-58367)

CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the Delta class when processing user-controlled input passed to the constructor. A remote attacker can supply crafted Delta data to modify deepdiff.serialization.SAFE_TO_IMPORT and trigger unsafe pickle deserialization to execute arbitrary code.

Only applications that pass untrusted user input directly into Delta are affected. Exploitation can use bytes input directly, and dictionary input may also be exploitable depending on the application.


Remediation

Install update from vendor's website.