Bug 2401936 - CVE-2025-61765 python-socketio: python-socketio code execution (RCE) via pickle deserialization [fedora-41]
Summary: CVE-2025-61765 python-socketio: python-socketio code execution (RCE) via pick...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: python-socketio
Version: 41
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Ben Beasley
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["5bda1fc5-c94f-4407-b4d0-d...
Depends On:
Blocks: CVE-2025-61765
TreeView+ depends on / blocked
 
Reported: 2025-10-06 17:47 UTC by Jon Moroney
Modified: 2025-10-06 19:28 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2025-10-06 19:28:51 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Moroney 2025-10-06 17:47:22 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams

Comment 1 Ben Beasley 2025-10-06 19:28:51 UTC
I can’t update python-socketio past 5.11.4-1 in Fedora 41. I don’t remember if this is for dependency reasons or compatibility / breaking change reasons, but I remember that there were good reasons.

It should be possible to backport the fix from https://github.com/miguelgrinberg/python-socketio/commit/53f6be094257ed81476b0e212c8cddd6d06ca39a to 5.11.4, and I considered doing so, but the patch is not very small, and there has been quite a bit of change upstream since 5.11.4, so the risk of introducing a regression or accidental incompatibility is not quite small enough to ignore.

Considering this, my doubts that the particular circumstances in which this can be exploited (“multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications”) can ever occur when python-socketio is used as a dependency for pgadmin4, and the mere month and a half remaining until Fedora 41 end-of-life, I’m not planning to prepare an update for this issue in Fedora 41.

Users who are concerned about this CVE should consider expediting their plans to upgrade to Fedora 42 or 43, where updates that would resolve this CVE are now in testing.


Note You need to log in before you can comment on or make changes to this bug.