OESA-2026-2515

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2515
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2515.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2515
Upstream
Published
2026-05-29T11:11:28Z
Modified
2026-08-18T01:20:01.759183043Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
python-pillow security update
Details

Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift. of CVE-2022-22815,CVE-2022-22816)

Security Fix(es):

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.(CVE-2026-42308)

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.(CVE-2026-42310)

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.(CVE-2026-42311)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP1 / python-pillow

Package

Name
python-pillow
Purl
pkg:rpm/openEuler/python-pillow&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.3.0-5.oe2403sp1

Ecosystem specific

{
    "x86_64": [
        "python-pillow-debuginfo-10.3.0-5.oe2403sp1.x86_64.rpm",
        "python-pillow-debugsource-10.3.0-5.oe2403sp1.x86_64.rpm",
        "python3-pillow-10.3.0-5.oe2403sp1.x86_64.rpm",
        "python3-pillow-devel-10.3.0-5.oe2403sp1.x86_64.rpm",
        "python3-pillow-qt-10.3.0-5.oe2403sp1.x86_64.rpm",
        "python3-pillow-tk-10.3.0-5.oe2403sp1.x86_64.rpm"
    ],
    "aarch64": [
        "python-pillow-debuginfo-10.3.0-5.oe2403sp1.aarch64.rpm",
        "python-pillow-debugsource-10.3.0-5.oe2403sp1.aarch64.rpm",
        "python3-pillow-10.3.0-5.oe2403sp1.aarch64.rpm",
        "python3-pillow-devel-10.3.0-5.oe2403sp1.aarch64.rpm",
        "python3-pillow-qt-10.3.0-5.oe2403sp1.aarch64.rpm",
        "python3-pillow-tk-10.3.0-5.oe2403sp1.aarch64.rpm"
    ],
    "src": [
        "python-pillow-10.3.0-5.oe2403sp1.src.rpm"
    ],
    "noarch": [
        "python3-pillow-help-10.3.0-5.oe2403sp1.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2515.json"