#1108057 protobuf: CVE-2025-4565

Package:
src:protobuf
Source:
src:protobuf
Submitter:
Salvatore Bonaccorso
Date:
2025-06-19 18:57:02 UTC
Severity:
normal
Tags:
#1108057#5
Date:
2025-06-19 18:56:18 UTC
From:
To:
Hi,

The following vulnerability was published for protobuf.

CVE-2025-4565[0]:
| Any project that uses Protobuf Pure-Python backend to parse
| untrusted Protocol Buffers data containing an arbitrary number of
| recursive groups, recursive messages or a series of SGROUP tags can
| be corrupted by exceeding the Python recursion limit. This can
| result in a Denial of service by crashing the application with a
| RecursionError. We recommend upgrading to version =>6.31.1 or beyond
| commit 17838beda2943d08b8a9d4df5b68f5f04f26d901


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-4565
https://www.cve.org/CVERecord?id=CVE-2025-4565
[1] https://github.com/protocolbuffers/protobuf/commit/17838beda2943d08b8a9d4df5b68f5f04f26d901

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore