SB2025091586 - Fedora 42 update for python-deepdiff, python-orderly-set
Published: September 15, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the Delta class when processing user-controlled input passed to the constructor. A remote attacker can supply crafted Delta data to modify deepdiff.serialization.SAFE_TO_IMPORT and trigger unsafe pickle deserialization to execute arbitrary code.
Only applications that pass untrusted user input directly into Delta are affected. Exploitation can use bytes input directly, and dictionary input may also be exploitable depending on the application.
Remediation
Install update from vendor's website.