Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

openSUSE: CVE-2025-58367 in python-deepdiff Denial of Service Risk Level

opensuse
Calendar Grey September 10, 2025
Dist Opensuse Esm H88
A vital security update for python-deepdiff has been released, fixing vulnerabilities that could enable remote code execution and DoS attacks, especially on openSUSE systems
An update that solves one vulnerability can now be installed.

Description

This update for python-deepdiff fixes the following issues:

* CVE-2025-58367: class pollution via the `Delta` class constructor can lead

to denial-of-service and remote code execution (bsc#1249347).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch SUSE-2025-3127=1 openSUSE-SLE-15.6-2025-3127=1

Package List

* openSUSE Leap 15.6 (noarch)

* python311-deepdiff-6.3.0-150600.3.3.1

References

* bsc#1249347

## References:

* https://www.suse.com/security/cve/CVE-2025-58367.html

* https://bugzilla.suse.com/show_bug.cgi?id=1249347

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:03127-1
Release Date: 2025-09-10T08:49:39Z
Affected Products: * openSUSE Leap 15.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here