Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-15947

Опубликовано: 23 июн. 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость функции FontFile.compile() файла PIL/FontFile.py библиотеки для работы с изображениями Python Pillow связана с неконтролируемым распределением памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Сообщество свободного программного обеспечения
Red Hat, Inc.
ООО «Ред Софт»
Fredrik Lundh and contributors

Наименование ПО

Debian GNU/Linux
Red Hat Enterprise Linux
РЕД ОС
Red Hat Satellite
Red Hat Ansible Automation Platform
Red Hat AI Inference Server
Red Hat Quay
Lightspeed Core
Red Hat Enterprise Linux AI
Exploit Intelligence
Pillow
Red Hat OpenShift AI

Версия ПО

9 (Debian GNU/Linux)
8 (Red Hat Enterprise Linux)
10 (Debian GNU/Linux)
11 (Debian GNU/Linux)
12 (Debian GNU/Linux)
7.3 (РЕД ОС)
6 (Red Hat Satellite)
2 (Red Hat Ansible Automation Platform)
8.4 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
8.6 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
6.16 for RHEL 8 (Red Hat Satellite)
6.16 for RHEL 9 (Red Hat Satellite)
2.5 for RHEL 8 (Red Hat Ansible Automation Platform)
2.5 for RHEL 9 (Red Hat Ansible Automation Platform)
8.8 Telecommunications Update Service (Red Hat Enterprise Linux)
8.8 Update Services for SAP Solutions (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
8.6 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
8.4 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
6.17 for RHEL 9 (Red Hat Satellite)
3.2 (Red Hat AI Inference Server)
3.12 (Red Hat Quay)
3.9 (Red Hat Quay)
3.14 (Red Hat Quay)
3.15 (Red Hat Quay)
3.16 (Red Hat Quay)
2.6 for RHEL 9 (Red Hat Ansible Automation Platform)
6.18 for RHEL 9 (Red Hat Satellite)
2.6 (Red Hat Ansible Automation Platform)
- (Lightspeed Core)
3.3 (Red Hat AI Inference Server)
3.3 (Red Hat Enterprise Linux AI)
- (Exploit Intelligence)
от 12.2.0 до 12.3.0 (Pillow)
3.10 (Red Hat Quay)
2.7 (Red Hat Ansible Automation Platform)
6.19 for RHEL 9 (Red Hat Satellite)
3.4 (Red Hat OpenShift AI)
3.4 (Red Hat AI Inference Server)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Сетевое программное средство

Операционные системы и аппаратные платформы

Сообщество свободного программного обеспечения Debian GNU/Linux 9
Red Hat, Inc. Red Hat Enterprise Linux 8
Сообщество свободного программного обеспечения Debian GNU/Linux 10
Сообщество свободного программного обеспечения Debian GNU/Linux 11
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «Ред Софт» РЕД ОС 7.3
Red Hat, Inc. Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat, Inc. Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat, Inc. Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat, Inc. Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Red Hat, Inc. Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat, Inc. Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
ООО «Ред Софт» РЕД ОС 8.0
Red Hat, Inc. Red Hat Enterprise Linux AI 3.3

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Python Pillow:
https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml
https://github.com/python-pillow/Pillow
https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst
https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-54060
https://deb.freexian.com/extended-lts/tracker/CVE-2026-54060
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/CVE-2026-54060
Для Ред ОС:
http://repo.red-soft.ru/redos/8.0/x86_64/updates/
http://repo.red-soft.ru/redos/7.3c/x86_64/updates/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 34%
0.00418
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.

CVSS3: 7.5
redhat
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.

CVSS3: 7.5
nvd
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.

CVSS3: 7.5
debian
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py F ...

CVSS3: 7.5
redos
около 2 месяцев назад

Уязвимость python-pillow

EPSS

Процентиль: 34%
0.00418
Низкий

7.5 High

CVSS3

7.8 High

CVSS2