MGASA-2026-0219

Source
https://advisories.mageia.org/MGASA-2026-0219.html
Import Source
https://advisories.mageia.org/MGASA-2026-0219.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0219
Upstream
  • CVE-2026-42308
  • CVE-2026-42310
Published
2026-06-18T07:22:53Z
Modified
2026-06-18T07:30:04.829687781Z
Summary
Updated python-pillow packages fix security vulnerabilities
Details

Integer overflow when processing fonts. (CVE-2026-42308) PDF Parsing Trailer Infinite Loop (DoS). (CVE-2026-42310)

References
Credits

Affected packages

Mageia:9 / python-pillow

Package

Name
python-pillow
Purl
pkg:rpm/mageia/python-pillow?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.2.0-3.3.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0219.json"