Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42311

Опубликовано: 09 мая 2026
Источник: debian

Описание

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed12.2.0-1package
pillownot-affectedbookwormpackage
pillownot-affectedbullseyepackage

Примечания

  • https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr

  • https://github.com/python-pillow/Pillow/pull/9520

  • Fixed by (merge): https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea (12.2.0)

  • Introduced by: https://github.com/python-pillow/Pillow/commit/c2907dc04967109391a77eea00f7d583a0a0395f (10.3.0)

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

CVSS3: 7.8
redhat
3 месяца назад

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

CVSS3: 7.8
nvd
3 месяца назад

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

CVSS3: 8.4
redos
20 дней назад

Уязвимость python-pillow

github
3 месяца назад

Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)