openSUSE-SU-2026:20831-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20831-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20831-1
Upstream
CVE (3)
Related
Published
2026-05-28T16:02:39Z
Modified
2026-05-30T23:15:09Z
Summary
Security update for python-Pillow
Details

This update for python-Pillow fixes the following issues

  • CVE-2026-42308: integer overflow in font processing can lead to denial of service (bsc#1265359).
  • CVE-2026-42309: heap buffer overflow when processing nested list coordinates (bsc#1265153).
  • CVE-2026-42310: infinite loop and resource exhaustion when processing specially crafted PDFs (bsc#1265154).
References

Affected packages