Bug 2373016 (CVE-2025-4565)

Summary: CVE-2025-4565 python-protobuf: Unbounded recursion in Python Protobuf
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: alinfoot, bbrownin, bdettelb, caswilli, dnakabaa, doconnor, dtrifiro, eglynn, haoli, hkataria, jajackso, jcammara, jjoyce, jkoehler, jmitchel, jneedle, jschluet, jtanner, jwendell, jwong, kaycoth, kegrant, kholdawa, koliveir, kshier, lcouzens, lhh, lphiri, lsvaty, mabashia, mburns, mgarciac, mskarbek, pbraun, pgrist, rbryant, rcernich, shvarugh, simaishi, smcdonal, stcannon, teagle, tfister, thavo, ttakamiy, weaton, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the python protobuf package which can result in a denial of service. Applications that parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages, or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application that integrates the package with a RecursionError.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2373047, 2373048, 2373049, 2373050    
Bug Blocks:    

Description OSIDB Bzimport 2025-06-16 15:01:23 UTC
Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion limit. This can result in a Denial of service by crashing the application with a RecursionError. We recommend upgrading to version =>6.31.1 or beyond commit 17838beda2943d08b8a9d4df5b68f5f04f26d901