Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

Critical Vulnerability in Fedora 42: python-unicodedata2 Arbitrary RCE

fedora
Calendar Grey December 20, 2025
Dist Fedora Esm H88
Important advisory for Fedora 42 on python-unicodedata2 addressing an arbitrary file write issue leading to remote code execution.
Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Summary

This module provides access to the Unicode Character Database (UCD)

which defines character properties for all Unicode characters. The

data contained in this database is compiled from the UCD version 13.0.0.

The versions of this package match Unicode versions, so unicodedata2==13.0.0

is data from Unicode 13.0.0.

Update Information:

Update to 17.0.0 version (#2412270) Update fonttools 4.61.0

Change Log

* Fri Nov 7 2025 Parag Nemade - 17.0.0-1 - Update to 17.0.0 version (#2412270) * Fri Jul 25 2025 Fedora Release Engineering - 16.0.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Thu Jul 10 2025 Parag Nemade - 16.0.0-4 - Convert a spec to use pyproject macros (rh#2378303) * Tue Jun 3 2025 Python Maint - 16.0.0-3 - Rebuilt for Python 3.14

References


[ 1 ] Bug #2421330 - CVE-2025-66034 fonttools: fontTools: Arbitrary file write leading to remote code execution via malicious .designspace file [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2421330

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-58e2bb0f1e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-unicodedata2
Product: Fedora 42
Version: 17.0.0
Release: 1.fc42
Summary: Unicodedata backport updated to the latest Unicode version

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here