Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-15952

Опубликовано: 21 июн. 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость функции GdImageFile._open() файла PIL/GdImageFile.py библиотеки для работы с изображениями Python Pillow связана с неконтролируемым распределением памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Сообщество свободного программного обеспечения
Red Hat, Inc.
ООО «Ред Софт»
Fredrik Lundh and contributors

Наименование ПО

Debian GNU/Linux
Red Hat Enterprise Linux
РЕД ОС
Red Hat Satellite
Red Hat Ansible Automation Platform
Red Hat AI Inference Server
Red Hat Quay
Lightspeed Core
Red Hat Enterprise Linux AI
Exploit Intelligence
Pillow
Red Hat OpenShift AI

Версия ПО

9 (Debian GNU/Linux)
8 (Red Hat Enterprise Linux)
10 (Debian GNU/Linux)
11 (Debian GNU/Linux)
12 (Debian GNU/Linux)
7.3 (РЕД ОС)
6 (Red Hat Satellite)
2 (Red Hat Ansible Automation Platform)
8.4 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
8.6 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
6.16 for RHEL 8 (Red Hat Satellite)
6.16 for RHEL 9 (Red Hat Satellite)
2.5 for RHEL 8 (Red Hat Ansible Automation Platform)
2.5 for RHEL 9 (Red Hat Ansible Automation Platform)
8.8 Telecommunications Update Service (Red Hat Enterprise Linux)
8.8 Update Services for SAP Solutions (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
8.6 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
8.4 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
6.17 for RHEL 9 (Red Hat Satellite)
3.2 (Red Hat AI Inference Server)
3.12 (Red Hat Quay)
3.9 (Red Hat Quay)
3.14 (Red Hat Quay)
3.15 (Red Hat Quay)
3.16 (Red Hat Quay)
2.6 for RHEL 9 (Red Hat Ansible Automation Platform)
6.18 for RHEL 9 (Red Hat Satellite)
2.6 (Red Hat Ansible Automation Platform)
- (Lightspeed Core)
3.3 (Red Hat AI Inference Server)
3.3 (Red Hat Enterprise Linux AI)
- (Exploit Intelligence)
от 12.2.0 до 12.3.0 (Pillow)
3.10 (Red Hat Quay)
2.7 (Red Hat Ansible Automation Platform)
6.19 for RHEL 9 (Red Hat Satellite)
3.4 (Red Hat OpenShift AI)
3.4 (Red Hat AI Inference Server)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Сетевое программное средство

Операционные системы и аппаратные платформы

Сообщество свободного программного обеспечения Debian GNU/Linux 9
Red Hat, Inc. Red Hat Enterprise Linux 8
Сообщество свободного программного обеспечения Debian GNU/Linux 10
Сообщество свободного программного обеспечения Debian GNU/Linux 11
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «Ред Софт» РЕД ОС 7.3
Red Hat, Inc. Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat, Inc. Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat, Inc. Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat, Inc. Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Red Hat, Inc. Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat, Inc. Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
ООО «Ред Софт» РЕД ОС 8.0
Red Hat, Inc. Red Hat Enterprise Linux AI 3.3

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Python Pillow:
https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2256.yaml
https://github.com/python-pillow/Pillow
https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst
https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675
https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-55380
https://deb.freexian.com/extended-lts/tracker/CVE-2026-55380
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/CVE-2026-55380
Для Ред ОС:
http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
http://repo.red-soft.ru/redos/8.0/x86_64/updates/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 34%
0.00418
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.

CVSS3: 7.5
redhat
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.

CVSS3: 7.5
nvd
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.

CVSS3: 7.5
debian
3 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.p ...

CVSS3: 7.5
redos
около 2 месяцев назад

Уязвимость python-pillow

EPSS

Процентиль: 34%
0.00418
Низкий

7.5 High

CVSS3

7.8 High

CVSS2